CVE-2021-3733

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-3733
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3733.json
Aliases
Related
Published
2022-03-10T17:42:59Z
Modified
2023-12-06T01:01:21.058749Z
Details

There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.

References

Affected packages

Git / github.com/python/cpython

Affected ranges