CVE-2021-33503

An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
Affected Products (NVD)
VendorProductVersion
pythonurllib3
1.25.4 ≤
𝑥
< 1.26.5
oracleenterprise_manager_ops_center
12.4.0.0
oracleinstantis_enterprisetrack
17.1
oracleinstantis_enterprisetrack
17.2
oracleinstantis_enterprisetrack
17.3
oraclezfs_storage_appliance_kit
8.8
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
python-urllib3
bookworm
1.26.12-1
fixed
bullseye
1.26.5-1~exp1
fixed
buster
not-affected
sid
2.0.7-2
fixed
stretch
not-affected
trixie
2.0.7-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python-pip
bionic
not-affected
focal
Fixed 20.0.2-5ubuntu1.7
released
groovy
ignored
hirsute
ignored
impish
not-affected
jammy
not-affected
kinetic
not-affected
trusty
not-affected
xenial
not-affected
python-urllib3
bionic
not-affected
focal
Fixed 1.25.8-2ubuntu0.2
released
groovy
ignored
hirsute
ignored
impish
not-affected
jammy
not-affected
kinetic
not-affected
trusty
not-affected
xenial
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
python-urllib3
suse enterprise sap 12
1.25.10-3.29.1
fixed
suse enterprise sap 12 SP3
1.25.10-3.29.1
fixed
suse enterprise sap 12 SP4
1.25.10-3.29.1
fixed
suse enterprise sap 12 SP5
1.25.10-3.29.1
fixed
suse enterprise server 12
1.25.10-3.29.1
fixed
suse enterprise server 12 SP3
1.25.10-3.29.1
fixed
suse enterprise server 12 SP4
1.25.10-3.29.1
fixed
suse enterprise server 12 SP5
1.25.10-3.29.1
fixed
python3-urllib3
suse enterprise sap 12
1.25.10-3.29.1
fixed
suse enterprise sap 12 SP3
1.25.10-3.29.1
fixed
suse enterprise sap 12 SP4
1.25.10-3.29.1
fixed
suse enterprise sap 12 SP5
1.25.10-3.29.1
fixed
suse enterprise server 12
1.25.10-3.29.1
fixed
suse enterprise server 12 SP3
1.25.10-3.29.1
fixed
suse enterprise server 12 SP4
1.25.10-3.29.1
fixed
suse enterprise server 12 SP5
1.25.10-3.29.1
fixed
python311-urllib3
suse enterprise desktop 15 SP6
2.0.7-150400.7.11.1
fixed
suse enterprise sap 15 SP6
2.0.7-150400.7.11.1
fixed
suse enterprise server 15 SP6
2.0.7-150400.7.11.1
fixed
python311-urllib3_1
suse enterprise desktop 15 SP6
1.26.18-150600.1.4
fixed
suse enterprise sap 15 SP6
1.26.18-150600.1.4
fixed
suse enterprise server 15 SP6
1.26.18-150600.1.4
fixed
python36-urllib3
suse enterprise server 12 SP3
1.25.10-6.3.13
fixed