Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-46822 | CPython 3.9 and earlier doesn't disallow configuring an empty list ("[]") for SSLContext.set_npn_protocols() which is an invalid value for the underlying OpenSSL API. This results in a buffer over-read when NPN is used (see CVE-2024-5535 for OpenSSL). This vulnerability is of low severity due to NPN being not widely used and specifying an empty list likely being uncommon in-practice (typically a protocol name would be configured). |
Tue, 07 Oct 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 06 Nov 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
ssvc
|
Status: PUBLISHED
Assigner: PSF
Published:
Updated: 2026-04-21T20:12:42.468Z
Reserved: 2024-06-04T18:40:21.539Z
Link: CVE-2024-5642
Updated: 2024-08-01T21:18:06.642Z
Status : Deferred
Published: 2024-06-27T21:15:16.070
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-5642
OpenCVE Enrichment
Updated: 2025-07-12T22:45:00Z
EUVD