{"id":"CVE-2022-40899","aliases":["GHSA-v3c5-jqr6-7qm8","PYSEC-2022-42991"],"url":"https://o3.security/vulnerability/CVE-2022-40899","summary":"Python Charmers Future denial of service vulnerability","details":"An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server.","published":"2022-12-22T00:00:00Z","modified":"2026-08-12T03:51:42.022754315Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.01819,"percentile":0.76748,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"PyPI","name":"future","fixedVersion":"0.18.3"}],"fix":{"url":"https://github.com/PythonCharmers/python-future/pull/610","label":"PythonCharmers/python-future#610"},"references":[{"type":"WEB","url":"https://github.com/PythonCharmers/python-future/blob/master/src/future/backports/http/cookiejar.py#L215"},{"type":"WEB","url":"https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/40xxx/CVE-2022-40899.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-40899"},{"type":"FIX","url":"https://github.com/PythonCharmers/python-future/pull/610"},{"type":"FIX","url":"https://github.com/python/cpython/pull/17157"},{"type":"PACKAGE","url":"https://pypi.org/project/future/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:42.022754315Z"}}