CVE-2021-33503
Summary
| CVE | CVE-2021-33503 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-29 11:15:00 UTC |
| Updated | 2023-11-07 03:35:00 UTC |
| Description | An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 33 Update: python-urllib3-1.25.8-5.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: python-urllib3-1.25.10-5.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: python-urllib3-1.25.8-5.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Improve performance of sub-authority splitting in URL · urllib3/urllib3@2d4a3fe · GitHub |
CONFIRM |
github.com |
|
| urllib3: Multiple vulnerabilities (GLSA 202107-36) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| Catastrophic backtracking in URL authority parser when passed URL containing many @ characters · CVE-2021-33503 · GitHub Advisory Database · GitHub |
CONFIRM |
github.com |
|
| Oracle Critical Patch Update Advisory - October 2021 |
MISC |
www.oracle.com |
|
| [SECURITY] Fedora 34 Update: python-urllib3-1.25.10-5.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159466 Oracle Enterprise Linux Security Update for python39:3.9 and python39-devel:3.9 (ELSA-2021-4160)
- 159467 Oracle Enterprise Linux Security Update for python38:3.8 and python38-devel:3.8 (ELSA-2021-4162)
- 180065 Debian Security Update for python-urllib3 (CVE-2021-33503)
- 199120 Ubuntu Security Notification for urllib3 Vulnerability (USN-5812-1)
- 239580 Red Hat Update for rh-python38 (RHSA-2021:3254)
- 239841 Red Hat Update for python39:3.9 and python39-devel:3.9 (RHSA-2021:4160)
- 239845 Red Hat Update for python38:3.8 and python38-devel:3.8 (RHSA-2021:4162)
- 239895 Red Hat Update for Satellite 6.10 (RHSA-2021:4702)
- 281655 Fedora Security Update for mingw (FEDORA-2021-b14975e43d)
- 281676 Fedora Security Update for python (FEDORA-2021-a6bde7ab18)
- 281699 Fedora Security Update for python (FEDORA-2021-9c5f3b8aae)
- 296060 Oracle Solaris 11.4 Support Repository Update (SRU) 37.0.1.101.1 Missing (CPUJUL2021)
- 352486 Amazon Linux Security Advisory for python-urllib3: ALAS2-2021-1688
- 378599 Splunk Enterprise Third Party Package Updates for June (SVD-2023-0613)
- 672442 EulerOS Security Update for python-pip (EulerOS-SA-2022-2854)
- 672444 EulerOS Security Update for python-pip (EulerOS-SA-2022-2828)
- 710032 Gentoo Linux urllib3 Multiple vulnerabilities (GLSA 202107-36)
- 750668 SUSE Enterprise Linux Security Update for python-urllib3 (SUSE-SU-2021:2012-1)
- 750818 OpenSUSE Security Update for python-urllib3 (openSUSE-SU-2021:2012-1)
- 900143 CBL-Mariner Linux Security Update for python-urllib3 1.25.9
- 901983 Common Base Linux Mariner (CBL-Mariner) Security Update for python-urllib3 (6821-1)
- 903190 Common Base Linux Mariner (CBL-Mariner) Security Update for python-urllib3 (4373)
- 940526 AlmaLinux Security Update for python38:3.8 and python38-devel:3.8 (ALSA-2021:4162)
- 940559 AlmaLinux Security Update for python39:3.9 and python39-devel:3.9 (ALSA-2021:4160)
- 960239 Rocky Linux Security Update for python39:3.9 and python39-devel:3.9 (RLSA-2021:4160)
- 960342 Rocky Linux Security Update for python38:3.8 and python38-devel:3.8 (RLSA-2021:4162)
- 980359 Python (pip) Security Update for urllib3 (GHSA-q2q7-5pp4-w6pg)