CVE-2021-33503
published 2021-06-29CVE-2021-33503: An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.27%
87.0th percentile
An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | python-urllib3 | < python-urllib3 1.26.5-1~exp1 (bookworm) | python-urllib3 1.26.5-1~exp1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | azl3_mozjs_102.15.1-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_python-urllib3_1.25.9-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python-virtualenv_20.26.6-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_python-urllib3_1.25.9-2_on_cbl_mariner_1.0 | — | — |
| oracle | enterprise_manager_ops_center | — | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | instantis_enterprisetrack | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
| python | urllib3 | >= 1.25.4 < 1.26.5 | 1.26.5 |
| urllib3 | urllib3 | >= 1.25.4 < 1.26.5 | 1.26.5 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
ghsa7.5HIGH
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2021-33503: An issue was discovered in urllib3 before 1
osv·2021-06-29·CVSS 7.5
CVE-2021-33503 [HIGH] CVE-2021-33503: An issue was discovered in urllib3 before 1
An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.
OSV
Catastrophic backtracking in URL authority parser when passed URL containing many @ characters
osv·2021-06-01·CVSS 7.5
CVE-2021-33503 [HIGH] Catastrophic backtracking in URL authority parser when passed URL containing many @ characters
Catastrophic backtracking in URL authority parser when passed URL containing many @ characters
### Impact
When provided with a URL containing many `@` characters in the authority component the authority regular expression exhibits catastrophic backtracking causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.
### Patches
The issue has been fixed in urllib3 v1.26.5.
### References
- [CVE-2021-33503](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33503)
- [JVNVU#92413403 (English)](https://jvn.jp/en/vu/JVNVU92413403/)
- [JVNVU#92413403 (Japanese)](https://jvn.jp/vu/JVNVU92413403/)
- [urllib3 v1.26.5](https://github.com/urllib3/urllib3/releases/tag/1.26.5)
### For more information
If you have any questions or comments about thi
GHSA
Catastrophic backtracking in URL authority parser when passed URL containing many @ characters
ghsa·2021-06-01·CVSS 7.5
CVE-2021-33503 [HIGH] CWE-400 Catastrophic backtracking in URL authority parser when passed URL containing many @ characters
Catastrophic backtracking in URL authority parser when passed URL containing many @ characters
### Impact
When provided with a URL containing many `@` characters in the authority component the authority regular expression exhibits catastrophic backtracking causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.
### Patches
The issue has been fixed in urllib3 v1.26.5.
### References
- [CVE-2021-33503](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33503)
- [JVNVU#92413403 (English)](https://jvn.jp/en/vu/JVNVU92413403/)
- [JVNVU#92413403 (Japanese)](https://jvn.jp/vu/JVNVU92413403/)
- [urllib3 v1.26.5](https://github.com/urllib3/urllib3/releases/tag/1.26.5)
### For more information
If you have any questions or comments about thi
Ubuntu
urllib3 vulnerability
vendor_ubuntu·2023-01-19
CVE-2021-33503 urllib3 vulnerability
Title: urllib3 vulnerability
Summary: urllib3 could be made to stop responding if it received specially crafted
network traffic.
It was discovered that urllib3 incorrectly handled certain characters
in URLs. A remote attacker could possibly use this issue to cause urllib3
to consume resources, leading to a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component the authority regular expression exhibits catastrophic backtracking c
vendor_msrc·2021-06-08·CVSS 7.5
CVE-2021-33503 [HIGH] CWE-400 An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component the authority regular expression exhibits catastrophic backtracking c
An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component the authority regular expression exhibits catastrophic backtracking causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See th
Red Hat
python-urllib3: ReDoS in the parsing of authority part of URL
vendor_redhat·2021-06-01·CVSS 7.5
CVE-2021-33503 [HIGH] CWE-835 python-urllib3: ReDoS in the parsing of authority part of URL
python-urllib3: ReDoS in the parsing of authority part of URL
An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.
A flaw was found in python-urllib3. When provided with a URL containing many @ characters in the authority component, the authority's regular expression exhibits catastrophic backtracking. This flaw causes a denial of service if a URL is passed as a parameter or redirected via an HTTP redirect. The highest threat from this vulnerability is to system availability.
Statement: * Red Hat OpenShift Container Platform (OCP) 4 deliver
Debian
CVE-2021-33503: python-urllib3 - An issue was discovered in urllib3 before 1.26.5. When provided with a URL conta...
vendor_debian·2021·CVSS 7.5
CVE-2021-33503 [HIGH] CVE-2021-33503: python-urllib3 - An issue was discovered in urllib3 before 1.26.5. When provided with a URL conta...
An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.
Scope: local
bookworm: resolved (fixed in 1.26.5-1~exp1)
bullseye: resolved (fixed in 1.26.5-1~exp1)
forky: resolved (fixed in 1.26.5-1~exp1)
sid: resolved (fixed in 1.26.5-1~exp1)
trixie: resolved (fixed in 1.26.5-1~exp1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/advisories/GHSA-q2q7-5pp4-w6pghttps://github.com/urllib3/urllib3/commit/2d4a3fee6de2fa45eb82169361918f759269b4echttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6SCV7ZNAHS3E6PBFLJGENCDRDRWRZZ6W/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FMUGWEAUYGGHTPPXT6YBD53WYXQGVV73/https://security.gentoo.org/glsa/202107-36https://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://github.com/advisories/GHSA-q2q7-5pp4-w6pghttps://github.com/urllib3/urllib3/commit/2d4a3fee6de2fa45eb82169361918f759269b4echttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6SCV7ZNAHS3E6PBFLJGENCDRDRWRZZ6W/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FMUGWEAUYGGHTPPXT6YBD53WYXQGVV73/https://security.gentoo.org/glsa/202107-36https://www.oracle.com/security-alerts/cpuoct2021.html
2021-06-29
Published