AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2020-14422.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 5.9CVSS 3.1 · nvd@nist.gov
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSModifiedModified Oct 08, 2026

Disclosure summary

Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by the performance of a dictionary containing IPv4Interface or IPv6Interface objects, and this attacker can cause many dictionary entries to be created. This is fixed in: v3.5.10, v3.5.10rc1; v3.6.12; v3.7.9; v3.8.4, v3.8.4rc1, v3.8.5, v3.8.6, v3.8.6rc1; v3.9.0, v3.9.0b4, v3.9.0b5, v3.9.0rc1, v3.9.0rc2.

Source-reported weakness categories

CWE-330, CWE-682

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

NIST National Vulnerability Database · NVD-CVE-2020-14422

Open original source · Updated Oct 08, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

VendorProduct / associationVersion / bounds
pythonpython* {"versionStartIncluding":"3.8.0","versionEndExcluding":"3.8.4"}
opensuseleap15.1
opensuseleap15.2
fedoraprojectfedora31
fedoraprojectfedora32
oracleenterprise_manager_ops_center12.4.0.0

Original records & references

PUBLISHED 2020-06-18T10:15:11-04:00
MODIFIED 2026-10-08T17:17:23-04:00
INGESTED 2026-10-10T20:50:19-04:00