Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2018-14647
The Python Project Python — Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization.
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U N N H 7.5 .1091 95.8 —
AFFECTED
Product Versions Fixed
Python 3.8, 3.7, 3.6, 3.5, 3.4, 2.7 – —
TIMELINE
Jul 27 Reserved by redhat
Sep 25 Published (CNA: redhat)
Oct 7 RESCORED — CVE-2018-14647 (The Python Project Python). CVSS 5.3 → 7.5 (NVD).
Description
Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming large amounts CPU and RAM. The vulnerability exists in Python versions 3.7.0, 3.6.0 through 3.6.6, 3.5.0 through 3.5.6, 3.4.0 through 3.4.9, 2.7.0 through 2.7.15.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| July 27, 2018 | Reserved | Reserved by redhat |
| September 25, 2018 | Published | Published (CNA: redhat) |
| October 7, 2026 | RESCORED | RESCORED — CVE-2018-14647 (The Python Project Python). CVSS 5.3 → 7.5 (NVD). |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| The Python Project | Python | — | 3.8, 3.7, 3.6, 3.5, 3.4, 2.7 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2018-14647 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Thursday, October 8, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.