Back

HIGH

python-flask: unexpected memory usage can lead to denial of service via crafted encoded JSON data

Published Jul 17, 2019

Description

The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded JSON data. The fixed version is: 1. NOTE: this may overlap CVE-2018-1000656.

Affected products

Remediation

Red Hat statement

Red Hat Satellite 6.5 ships an affected version of python-flask. However, the product is not vulnerable since the data component Crane receives from pulp_docker repository metadata with JSON uses UTF-8 encoding by default. Other supported versions of the Satellite are not affected by this vulnerability. Note: CVE-2019-1010083 is a duplicate of the flaw in CVE-2018-1000656. However, the 2019 flaw identifies newer affected products.

References (10)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner dwf
Published Jul 17, 2019
Updated Aug 5, 2024
Reserved Mar 20, 2019

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Apr 26, 2018
Bugzilla 1888007

ENISA EUVD

Assigner dwf
Published Jul 17, 2019
Updated Aug 5, 2024