A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability.
Conclusion & alert: CVE-2020-10735 is rated Moderate Risk (51/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.40%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-28 | 0.46% | 0.40% | -0.06% |
| 2 | 2026-03-26 | 0.29% | 0.46% | +0.17% |
| 3 | 2026-03-21 | — | 0.29% | — |
Full EPSS history (26 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2020-10735 not yet assigned priority: Debian including 4 source packages (pypy3, python2.7, python3.11, python3.9), 8 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 7, open 1. | https://security-tracker.debian.org/tracker/CVE-2020-10735 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2020-10735 |
suse
|
high | CVE-2020-10735 severity important: SUSE including 562 source package names (0.0.17-1.1:libpython3_6m1_0-3.6.15-150300.10.37.2, 0.0.17-1.1:python3-3.6.15-150300.10.37.2, …), 2313 product×package rows across 432 product lines (Container bci/bci-base-fips, Container bci/bci-sle15-kernel-module-devel, … (432 product lines)): Fixed 2053, Will Not Fix 139, Known Affected 116, Known Not Affected 5. | https://www.suse.com/security/cve/CVE-2020-10735/ |
ubuntu
|
negligible | CVE-2020-10735 negligible priority: Ubuntu including 9 source packages (python, python2.7, …), 56 status rows across 7 suites (bionic, focal, jammy, kinetic, trusty, upstream, xenial): ignored 29, DNE 18, needs-triage 9. | https://ubuntu.com/security/CVE-2020-10735 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| python | python | >= 3.7.0, < 3.7.14 | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
| python | python | >= 3.8.0, < 3.8.14 | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
| python | python | >= 3.9.0, < 3.9.14 | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
| python | python | >= 3.10.0, < 3.10.7 | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
| python | python | 3.11.0 | cpe:2.3:a:python:python:3.11.0:alpha1:*:*:*:*:*:* |
| python | python | 3.11.0 | cpe:2.3:a:python:python:3.11.0:alpha2:*:*:*:*:*:* |
| python | python | 3.11.0 | cpe:2.3:a:python:python:3.11.0:alpha3:*:*:*:*:*:* |
| python | python | 3.11.0 | cpe:2.3:a:python:python:3.11.0:alpha4:*:*:*:*:*:* |
| python | python | 3.11.0 | cpe:2.3:a:python:python:3.11.0:alpha5:*:*:*:*:*:* |
| python | python | 3.11.0 | cpe:2.3:a:python:python:3.11.0:alpha6:*:*:*:*:*:* |
| python | python | 3.11.0 | cpe:2.3:a:python:python:3.11.0:alpha7:*:*:*:*:*:* |
| python | python | 3.11.0 | cpe:2.3:a:python:python:3.11.0:beta1:*:*:*:*:*:* |
| python | python | 3.11.0 | cpe:2.3:a:python:python:3.11.0:beta2:*:*:*:*:*:* |
| python | python | 3.11.0 | cpe:2.3:a:python:python:3.11.0:beta3:*:*:*:*:*:* |
| python | python | 3.11.0 | cpe:2.3:a:python:python:3.11.0:beta4:*:*:*:*:*:* |
| python | python | 3.11.0 | cpe:2.3:a:python:python:3.11.0:beta5:*:*:*:*:*:* |
| python | python | 3.11.0 | cpe:2.3:a:python:python:3.11.0:rc1:*:*:*:*:*:* |
| redhat | quay | 3.0.0 | cpe:2.3:a:redhat:quay:3.0.0:*:*:*:*:*:*:* |
| redhat | software_collections | — | cpe:2.3:a:redhat:software_collections:-:*:*:*:*:*:*:* |
| fedoraproject | fedora | 35 | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* |
| fedoraproject | fedora | 36 | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* |
| fedoraproject | fedora | 37 | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
| redhat | enterprise_linux | 8.0 | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* |