Python Missing Initialization of Resource Vulnerability - CVE-2018-14647
Python39s elementtree C accelerator failed to initialise Expat39s hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat39s internal data structures consuming large amounts CPU and RAM. The vulnerability exists in Python versions 3.7.0 3.6.0 through 3.6.6 3.5.0 through 3.5.6 3.4.0 through 3.4.9 2.7.0 through 2.7.15.