CVE-2021-3733

MEDIUM

urllib - ReDOS

Title source: llm
STIX 2.1

Description

There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.

Scores

CVSS v3 6.5
EPSS 0.0063
EPSS Percentile 70.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-400
Status published
Products (24)
fedoraproject/extra_packages_for_enterprise_linux 7.0
fedoraproject/fedora 33
fedoraproject/fedora 34
fedoraproject/fedora 35
fedoraproject/fedora 36
netapp/hci_compute_node_firmware
netapp/management_services_for_element_software_and_netapp_hci
netapp/ontap_select_deploy_administration_utility
netapp/solidfire\,_enterprise_sds_\&_hci_storage_node
python/python 3.10.0
... and 14 more
Published Mar 10, 2022
Tracked Since Feb 18, 2026