CVE-2022-45061 - CVE House
Back to Database
Status published Unknown CVE-2022-45061

An issue was discovered in Python before 3.11.1. An unnecessary...

Vulnerability Description

An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote servers that could be controlled by a malicious actor; in such a scenario, they could trigger excessive CPU consumption on the client attempting to make use of an attacker-supplied supposed hostname. For example, the attack payload could be placed in the Location header of an HTTP response with status code 302. A fix is planned in 3.11.1, 3.10.9, 3.9.16, 3.8.16, and 3.7.16.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-45061

Credits & Attribution

No credits recorded in the NVD database.

References

Affected Vendor

Affected Software

python, fedora, active iq unified manager, e-series performance analyzer, element software, hci, management services for element software, ontap select deploy administration utility, bootstrap os
Vulnerable Versions:
0, 3.8.0, 3.9.0, 3.10.0, 3.11.0, 35, 36, 37

Timeline

Official Publish: November 9th, 2022
Last Modified: November 3rd, 2025
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.