CVE-2021-32837Regex Denial of Service in Mechanize

Severity
7.5HIGHNVD
EPSS
2.8%
top 13.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 17
Latest updateJan 18

Description

mechanize, a library for automatically interacting with HTTP web servers, contains a regular expression that is vulnerable to regular expression denial of service (ReDoS) prior to version 0.4.6. If a web server responds in a malicious way, then mechanize could crash. Version 0.4.6 has a patch for the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

debiandebian/python-mechanize< python-mechanize 1:0.4.7-1 (bookworm)
CVEListV5python-mechanize/mechanize0.4.60.4.6

Patches

🔴Vulnerability Details

3
OSV
mechanize Regular Expression Denial of Service vulnerability2023-01-18
GHSA
mechanize Regular Expression Denial of Service vulnerability2023-01-18
OSV
CVE-2021-32837: mechanize, a library for automatically interacting with HTTP web servers, contains a regular expression that is vulnerable to regular expression denia2023-01-17

📋Vendor Advisories

1
Debian
CVE-2021-32837: python-mechanize - mechanize, a library for automatically interacting with HTTP web servers, contai...2021