CVE Vulnerabilities

CVE-2020-10735

Incorrect Type Conversion or Cast

Published: Sep 09, 2022 | Modified: Nov 03, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
NEGLIGIBLE
root.io logo minimus.io logo echo.ai logo

A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int(text), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability.

Weakness

The product does not correctly convert an object, resource, or structure from one type to a different type.

Affected Software

NameVendorStart VersionEnd Version
PythonPython3.7.0 (including)3.7.14 (excluding)
PythonPython3.8.0 (including)3.8.14 (excluding)
PythonPython3.9.0 (including)3.9.14 (excluding)
PythonPython3.10.0 (including)3.10.7 (excluding)
PythonPython3.11.0-alpha1 (including)3.11.0-alpha1 (including)
PythonPython3.11.0-alpha2 (including)3.11.0-alpha2 (including)
PythonPython3.11.0-alpha3 (including)3.11.0-alpha3 (including)
PythonPython3.11.0-alpha4 (including)3.11.0-alpha4 (including)
PythonPython3.11.0-alpha5 (including)3.11.0-alpha5 (including)
PythonPython3.11.0-alpha6 (including)3.11.0-alpha6 (including)
PythonPython3.11.0-alpha7 (including)3.11.0-alpha7 (including)
PythonPython3.11.0-beta1 (including)3.11.0-beta1 (including)
PythonPython3.11.0-beta2 (including)3.11.0-beta2 (including)
PythonPython3.11.0-beta3 (including)3.11.0-beta3 (including)
PythonPython3.11.0-beta4 (including)3.11.0-beta4 (including)
PythonPython3.11.0-beta5 (including)3.11.0-beta5 (including)
PythonPython3.11.0-rc1 (including)3.11.0-rc1 (including)
Red Hat Enterprise Linux 8RedHatpython3-0:3.6.8-48.el8_7.1*
Red Hat Enterprise Linux 8RedHatpython38:3.8-8080020221221151857.0d9ba776*
Red Hat Enterprise Linux 8RedHatpython38-devel:3.8-8080020221221151857.0d9ba776*
Red Hat Enterprise Linux 8RedHatpython39:3.9-8080020221221152015.aed85c85*
Red Hat Enterprise Linux 8RedHatpython39-devel:3.9-8080020221221152015.aed85c85*
Red Hat Enterprise Linux 8RedHatpython39:3.9-8080020221221152015.aed85c85*
Red Hat Enterprise Linux 8RedHatpython39-devel:3.9-8080020221221152015.aed85c85*
Red Hat Enterprise Linux 8RedHatpython3-0:3.6.8-48.el8_7.1*
Red Hat Enterprise Linux 8.6 Extended Update SupportRedHatpython3-0:3.6.8-47.el8_6.4*
Red Hat Enterprise Linux 9RedHatpython3.9-0:3.9.10-3.el9_0*
Red Hat Enterprise Linux 9RedHatpython3.9-0:3.9.10-3.el9_0*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHatrh-python38-python-0:3.8.14-1.el7*
PythonUbuntutrusty*
PythonUbuntuxenial*
Python2.7Ubuntubionic*
Python2.7Ubuntudevel*
Python2.7Ubuntuesm-apps/focal*
Python2.7Ubuntuesm-apps/jammy*
Python2.7Ubuntuesm-infra-legacy/trusty*
Python2.7Ubuntuesm-infra/bionic*
Python2.7Ubuntuesm-infra/xenial*
Python2.7Ubuntufocal*
Python2.7Ubuntujammy*
Python2.7Ubuntukinetic*
Python2.7Ubuntuprecise/esm*
Python2.7Ubuntutrusty*
Python2.7Ubuntutrusty/esm*
Python2.7Ubuntuvivid/ubuntu-core*
Python2.7Ubuntuxenial*
Python3.10Ubuntudevel*
Python3.10Ubuntujammy*
Python3.10Ubuntukinetic*
Python3.10Ubuntutrusty*
Python3.10Ubuntuxenial*
Python3.4Ubuntuesm-infra-legacy/trusty*
Python3.4Ubuntutrusty*
Python3.4Ubuntutrusty/esm*
Python3.4Ubuntuvivid/stable-phone-overlay*
Python3.4Ubuntuvivid/ubuntu-core*
Python3.4Ubuntuxenial*
Python3.5Ubuntuesm-infra-legacy/trusty*
Python3.5Ubuntuesm-infra/xenial*
Python3.5Ubuntutrusty*
Python3.5Ubuntutrusty/esm*
Python3.5Ubuntuxenial*
Python3.6Ubuntubionic*
Python3.6Ubuntuesm-infra/bionic*
Python3.6Ubuntutrusty*
Python3.6Ubuntuxenial*
Python3.7Ubuntubionic*
Python3.7Ubuntuesm-apps/bionic*
Python3.7Ubuntutrusty*
Python3.7Ubuntuxenial*
Python3.8Ubuntubionic*
Python3.8Ubuntuesm-apps/bionic*
Python3.8Ubuntuesm-infra/focal*
Python3.8Ubuntufocal*
Python3.8Ubuntutrusty*
Python3.8Ubuntuxenial*
Python3.9Ubuntuesm-apps/focal*
Python3.9Ubuntufocal*
Python3.9Ubuntutrusty*
Python3.9Ubuntuxenial*

References