Loading HuntDB...

GHSA-hrvr-7x5w-xpmq

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

CPython 3.9 and earlier doesn't disallow configuring an empty list ("[]") for SSLContext.set_npn_protocols() which is an invalid value for the underlying OpenSSL API. This results in a buffer over-read when NPN is used (see CVE-2024-5535 for OpenSSL). This vulnerability is of low severity due to NPN being not widely used and specifying an empty list likely being uncommon in-practice (typically a protocol name would be configured).

Related CVEs

Key Information

GHSA ID
GHSA-hrvr-7x5w-xpmq
Published
June 27, 2024 9:32 PM
Last Modified
November 7, 2024 12:30 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 12, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.