dnspython
DNS toolkit
Activity
- Latest release
- 1y ago
- Total releases
- 30
- Cadence
- ~42 days
- Last 12 months
- 0
Reach
- Stars
- —
Details
- License
- ISC
- First release
- Jul 22, 2013
| Version | Released | |
|---|---|---|
2.8.0
minor
| ||
2.8.0rc1
pre
| ||
2.7.0
minor
| ||
2.7.0rc1
pre
| ||
2.6.1
patch
| ||
2.6.0
minor
1 CVE
CVE-2023-29483
PYSEC-2026-1307
GHSA-3rq5-2g8h-59hc
PYSEC-2026-2472
Jul 07, 2026
Potential DoS via the Tudoor mechanism in eventlet and dnspython
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. Affected versions
1.0.0
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.2.0
1.3.0
+ 33 more Show less
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.5.0
1.6.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.3.0
2.3.0rc1
2.4.0
2.4.0rc1
2.4.1
2.4.2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
Fixed in
2.6.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.6.0rc1
pre
1 CVE
CVE-2023-29483
PYSEC-2026-1307
GHSA-3rq5-2g8h-59hc
PYSEC-2026-2472
Jul 07, 2026
Potential DoS via the Tudoor mechanism in eventlet and dnspython
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. Affected versions
1.0.0
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.2.0
1.3.0
+ 33 more Show less
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.5.0
1.6.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.3.0
2.3.0rc1
2.4.0
2.4.0rc1
2.4.1
2.4.2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
Fixed in
2.6.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.5.0
minor
1 CVE
CVE-2023-29483
PYSEC-2026-1307
GHSA-3rq5-2g8h-59hc
PYSEC-2026-2472
Jul 07, 2026
Potential DoS via the Tudoor mechanism in eventlet and dnspython
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. Affected versions
1.0.0
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.2.0
1.3.0
+ 33 more Show less
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.5.0
1.6.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.3.0
2.3.0rc1
2.4.0
2.4.0rc1
2.4.1
2.4.2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
Fixed in
2.6.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.5.0rc1
pre
1 CVE
CVE-2023-29483
PYSEC-2026-1307
GHSA-3rq5-2g8h-59hc
PYSEC-2026-2472
Jul 07, 2026
Potential DoS via the Tudoor mechanism in eventlet and dnspython
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. Affected versions
1.0.0
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.2.0
1.3.0
+ 33 more Show less
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.5.0
1.6.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.3.0
2.3.0rc1
2.4.0
2.4.0rc1
2.4.1
2.4.2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
Fixed in
2.6.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.4.2
patch
1 CVE
CVE-2023-29483
PYSEC-2026-1307
GHSA-3rq5-2g8h-59hc
PYSEC-2026-2472
Jul 07, 2026
Potential DoS via the Tudoor mechanism in eventlet and dnspython
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. Affected versions
1.0.0
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.2.0
1.3.0
+ 33 more Show less
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.5.0
1.6.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.3.0
2.3.0rc1
2.4.0
2.4.0rc1
2.4.1
2.4.2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
Fixed in
2.6.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.4.1
patch
1 CVE
CVE-2023-29483
PYSEC-2026-1307
GHSA-3rq5-2g8h-59hc
PYSEC-2026-2472
Jul 07, 2026
Potential DoS via the Tudoor mechanism in eventlet and dnspython
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. Affected versions
1.0.0
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.2.0
1.3.0
+ 33 more Show less
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.5.0
1.6.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.3.0
2.3.0rc1
2.4.0
2.4.0rc1
2.4.1
2.4.2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
Fixed in
2.6.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.4.0
minor
1 CVE
CVE-2023-29483
PYSEC-2026-1307
GHSA-3rq5-2g8h-59hc
PYSEC-2026-2472
Jul 07, 2026
Potential DoS via the Tudoor mechanism in eventlet and dnspython
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. Affected versions
1.0.0
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.2.0
1.3.0
+ 33 more Show less
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.5.0
1.6.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.3.0
2.3.0rc1
2.4.0
2.4.0rc1
2.4.1
2.4.2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
Fixed in
2.6.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.4.0rc1
pre
1 CVE
CVE-2023-29483
PYSEC-2026-1307
GHSA-3rq5-2g8h-59hc
PYSEC-2026-2472
Jul 07, 2026
Potential DoS via the Tudoor mechanism in eventlet and dnspython
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. Affected versions
1.0.0
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.2.0
1.3.0
+ 33 more Show less
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.5.0
1.6.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.3.0
2.3.0rc1
2.4.0
2.4.0rc1
2.4.1
2.4.2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
Fixed in
2.6.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.3.0
minor
1 CVE
CVE-2023-29483
PYSEC-2026-1307
GHSA-3rq5-2g8h-59hc
PYSEC-2026-2472
Jul 07, 2026
Potential DoS via the Tudoor mechanism in eventlet and dnspython
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. Affected versions
1.0.0
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.2.0
1.3.0
+ 33 more Show less
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.5.0
1.6.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.3.0
2.3.0rc1
2.4.0
2.4.0rc1
2.4.1
2.4.2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
Fixed in
2.6.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.3.0rc1
pre
1 CVE
CVE-2023-29483
PYSEC-2026-1307
GHSA-3rq5-2g8h-59hc
PYSEC-2026-2472
Jul 07, 2026
Potential DoS via the Tudoor mechanism in eventlet and dnspython
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. Affected versions
1.0.0
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.2.0
1.3.0
+ 33 more Show less
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.5.0
1.6.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.3.0
2.3.0rc1
2.4.0
2.4.0rc1
2.4.1
2.4.2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
Fixed in
2.6.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.2.1
patch
1 CVE
CVE-2023-29483
PYSEC-2026-1307
GHSA-3rq5-2g8h-59hc
PYSEC-2026-2472
Jul 07, 2026
Potential DoS via the Tudoor mechanism in eventlet and dnspython
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. Affected versions
1.0.0
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.2.0
1.3.0
+ 33 more Show less
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.5.0
1.6.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.3.0
2.3.0rc1
2.4.0
2.4.0rc1
2.4.1
2.4.2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
Fixed in
2.6.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.2.0
minor
1 CVE
CVE-2023-29483
PYSEC-2026-1307
GHSA-3rq5-2g8h-59hc
PYSEC-2026-2472
Jul 07, 2026
Potential DoS via the Tudoor mechanism in eventlet and dnspython
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. Affected versions
1.0.0
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.2.0
1.3.0
+ 33 more Show less
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.5.0
1.6.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.3.0
2.3.0rc1
2.4.0
2.4.0rc1
2.4.1
2.4.2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
Fixed in
2.6.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.2.0rc1
pre
1 CVE
CVE-2023-29483
PYSEC-2026-1307
GHSA-3rq5-2g8h-59hc
PYSEC-2026-2472
Jul 07, 2026
Potential DoS via the Tudoor mechanism in eventlet and dnspython
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. Affected versions
1.0.0
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.2.0
1.3.0
+ 33 more Show less
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.5.0
1.6.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.3.0
2.3.0rc1
2.4.0
2.4.0rc1
2.4.1
2.4.2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
Fixed in
2.6.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.1.0
minor
1 CVE
CVE-2023-29483
PYSEC-2026-1307
GHSA-3rq5-2g8h-59hc
PYSEC-2026-2472
Jul 07, 2026
Potential DoS via the Tudoor mechanism in eventlet and dnspython
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. Affected versions
1.0.0
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.2.0
1.3.0
+ 33 more Show less
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.5.0
1.6.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.3.0
2.3.0rc1
2.4.0
2.4.0rc1
2.4.1
2.4.2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
Fixed in
2.6.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.1.0rc1
pre
1 CVE
CVE-2023-29483
PYSEC-2026-1307
GHSA-3rq5-2g8h-59hc
PYSEC-2026-2472
Jul 07, 2026
Potential DoS via the Tudoor mechanism in eventlet and dnspython
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. Affected versions
1.0.0
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.2.0
1.3.0
+ 33 more Show less
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.5.0
1.6.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.3.0
2.3.0rc1
2.4.0
2.4.0rc1
2.4.1
2.4.2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
Fixed in
2.6.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.0
major
1 CVE
CVE-2023-29483
PYSEC-2026-1307
GHSA-3rq5-2g8h-59hc
PYSEC-2026-2472
Jul 07, 2026
Potential DoS via the Tudoor mechanism in eventlet and dnspython
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. Affected versions
1.0.0
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.2.0
1.3.0
+ 33 more Show less
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.5.0
1.6.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.3.0
2.3.0rc1
2.4.0
2.4.0rc1
2.4.1
2.4.2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
Fixed in
2.6.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.0rc2
pre
1 CVE
CVE-2023-29483
PYSEC-2026-1307
GHSA-3rq5-2g8h-59hc
PYSEC-2026-2472
Jul 07, 2026
Potential DoS via the Tudoor mechanism in eventlet and dnspython
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. Affected versions
1.0.0
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.2.0
1.3.0
+ 33 more Show less
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.5.0
1.6.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.3.0
2.3.0rc1
2.4.0
2.4.0rc1
2.4.1
2.4.2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
Fixed in
2.6.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
2.0.0rc1
pre
1 CVE
CVE-2023-29483
PYSEC-2026-1307
GHSA-3rq5-2g8h-59hc
PYSEC-2026-2472
Jul 07, 2026
Potential DoS via the Tudoor mechanism in eventlet and dnspython
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. Affected versions
1.0.0
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.2.0
1.3.0
+ 33 more Show less
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.5.0
1.6.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.3.0
2.3.0rc1
2.4.0
2.4.0rc1
2.4.1
2.4.2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
Fixed in
2.6.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.16.0
minor
1 CVE
CVE-2023-29483
PYSEC-2026-1307
GHSA-3rq5-2g8h-59hc
PYSEC-2026-2472
Jul 07, 2026
Potential DoS via the Tudoor mechanism in eventlet and dnspython
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. Affected versions
1.0.0
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.2.0
1.3.0
+ 33 more Show less
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.5.0
1.6.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.3.0
2.3.0rc1
2.4.0
2.4.0rc1
2.4.1
2.4.2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
Fixed in
2.6.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.15.0
minor
1 CVE
CVE-2023-29483
PYSEC-2026-1307
GHSA-3rq5-2g8h-59hc
PYSEC-2026-2472
Jul 07, 2026
Potential DoS via the Tudoor mechanism in eventlet and dnspython
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. Affected versions
1.0.0
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.2.0
1.3.0
+ 33 more Show less
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.5.0
1.6.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.3.0
2.3.0rc1
2.4.0
2.4.0rc1
2.4.1
2.4.2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
Fixed in
2.6.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.14.0
minor
1 CVE
CVE-2023-29483
PYSEC-2026-1307
GHSA-3rq5-2g8h-59hc
PYSEC-2026-2472
Jul 07, 2026
Potential DoS via the Tudoor mechanism in eventlet and dnspython
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. Affected versions
1.0.0
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.2.0
1.3.0
+ 33 more Show less
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.5.0
1.6.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.3.0
2.3.0rc1
2.4.0
2.4.0rc1
2.4.1
2.4.2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
Fixed in
2.6.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.13.0
minor
1 CVE
CVE-2023-29483
PYSEC-2026-1307
GHSA-3rq5-2g8h-59hc
PYSEC-2026-2472
Jul 07, 2026
Potential DoS via the Tudoor mechanism in eventlet and dnspython
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. Affected versions
1.0.0
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.2.0
1.3.0
+ 33 more Show less
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.5.0
1.6.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.3.0
2.3.0rc1
2.4.0
2.4.0rc1
2.4.1
2.4.2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
Fixed in
2.6.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.12.0
minor
1 CVE
CVE-2023-29483
PYSEC-2026-1307
GHSA-3rq5-2g8h-59hc
PYSEC-2026-2472
Jul 07, 2026
Potential DoS via the Tudoor mechanism in eventlet and dnspython
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. Affected versions
1.0.0
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.2.0
1.3.0
+ 33 more Show less
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.5.0
1.6.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.3.0
2.3.0rc1
2.4.0
2.4.0rc1
2.4.1
2.4.2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
Fixed in
2.6.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.11.1
patch
1 CVE
CVE-2023-29483
PYSEC-2026-1307
GHSA-3rq5-2g8h-59hc
PYSEC-2026-2472
Jul 07, 2026
Potential DoS via the Tudoor mechanism in eventlet and dnspython
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. Affected versions
1.0.0
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.2.0
1.3.0
+ 33 more Show less
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.5.0
1.6.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.3.0
2.3.0rc1
2.4.0
2.4.0rc1
2.4.1
2.4.2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
Fixed in
2.6.1
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
1.11.0
initial
1 CVE
CVE-2023-29483
PYSEC-2026-1307
GHSA-3rq5-2g8h-59hc
PYSEC-2026-2472
Jul 07, 2026
Potential DoS via the Tudoor mechanism in eventlet and dnspython
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1. Affected versions
1.0.0
1.1.0
1.10.0
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.2.0
1.3.0
+ 33 more Show less
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.5.0
1.6.0
1.7.1
1.8.0
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
2.0.0
2.0.0rc1
2.0.0rc2
2.1.0
2.1.0rc1
2.2.0
2.2.0rc1
2.2.1
2.3.0
2.3.0rc1
2.4.0
2.4.0rc1
2.4.1
2.4.2
2.5.0
2.5.0rc1
2.6.0
2.6.0rc1
Fixed in
2.6.1
References
Updated Jul 13, 2026 · Source: OSV.dev |