CVE-2021-3737
published 2022-03-04CVE-2021-3737: A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to…
PriorityP349high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
11.99%
95.7th percentile
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | pypy3 | < pypy3 7.3.8+dfsg-1 (bookworm) | pypy3 7.3.8+dfsg-1 (bookworm) |
| debian | python2.7 | < pypy3 7.3.8+dfsg-1 (bookworm) | pypy3 7.3.8+dfsg-1 (bookworm) |
| debian | python3.9 | < pypy3 7.3.8+dfsg-1 (bookworm) | pypy3 7.3.8+dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cm1_python3_3.7.11-1_on_cbl_mariner_1.0 | — | — |
| oracle | communications_cloud_native_core_binding_support_function | — | — |
| oracle | communications_cloud_native_core_network_exposure_function | — | — |
| oracle | communications_cloud_native_core_policy | — | — |
| python | python | — | — |
| python | python | >= 3.6.0 < 3.6.14 | 3.6.14 |
| python | python | >= 3.7.0 < 3.7.11 | 3.7.11 |
| python | python | >= 3.8.0 < 3.8.11 | 3.8.11 |
| python | python | >= 3.9.0 < 3.9.6 | 3.9.6 |
| redhat | codeready_linux_builder | — | — |
| redhat | codeready_linux_builder_for_ibm_z_systems | — | — |
| redhat | codeready_linux_builder_for_power_little_endian | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv7.6HIGH
vendor_ubuntu7.6HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_oracle6.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
osv·2024-07-11·CVSS 7.6
CVE-2015-20107 [HIGH] python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
It was discovered that Python incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.
(CVE-2015-20107)
It was discovered that Python incorrectly used regular expressions
vulnerable to catastrophic backtracking. A remote attacker could possibly
use this issue to cause a denial of service. This issue only affected
Ubuntu 14.04 LTS. (CVE-2018-1060, CVE-2018-1061)
It was discovered that Python failed to initialize Expat’s hash salt. A
remote attacker could possibly use this issue to cause hash collisions,
leading to a denial of service. This issue only affected Ubuntu 14.04 L
GHSA
GHSA-hr7v-m862-8hh8: A flaw was found in python
ghsa_unreviewed·2022-05-24
CVE-2021-3737 [LOW] CWE-400 GHSA-hr7v-m862-8hh8: A flaw was found in python
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.
OSV
CVE-2021-3737: A flaw was found in python
osv·2022-03-04·CVSS 7.5
CVE-2021-3737 [HIGH] CVE-2021-3737: A flaw was found in python
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.
OSV
python3.7, python3.8 vulnerabilities
osv·2021-12-17·CVSS 6.5
CVE-2020-8492 [MEDIUM] python3.7, python3.8 vulnerabilities
python3.7, python3.8 vulnerabilities
It was discovered that the urllib.request.AbstractBasicAuthHandler class
in Python contains regex allowing for catastrophic backtracking. Specially
crafted traffic from a malicious HTTP server could cause a regular expression
denial of service (ReDoS) condition for a client.
(CVE-2020-8492)
It was discovered that the urllib.request.AbstractBasicAuthHandler class
in Python contains regex with a quadratic worst-case time complexity.
Specially crafted traffic from a malicious HTTP server could cause a regular
expression denial of service (ReDoS) condition for a client.
(CVE-2021-3733)
It was discovered that the Python urllib http client could enter into an infinite
loop when incorrectly handling certain server responses (100 Continue response).
Speciall
OSV
python3.6 vulnerabilities
osv·2021-12-17·CVSS 6.5
CVE-2021-3733 [MEDIUM] python3.6 vulnerabilities
python3.6 vulnerabilities
It was discovered that the urllib.request.AbstractBasicAuthHandler class
in Python contains regex with a quadratic worst-case time complexity.
Specially crafted traffic from a malicious HTTP server could cause a regular
expression denial of service (ReDoS) condition for a client.
(CVE-2021-3733)
It was discovered that the Python urllib http client could enter into an infinite
loop when incorrectly handling certain server responses (100 Continue response).
Specially crafted traffic from a malicious HTTP server could cause a denial of
service (DoS) condition for a client.
(CVE-2021-3737)
OSV
python3.4, python3.5 vulnerabilities
osv·2021-09-16·CVSS 6.5
CVE-2021-3733 [MEDIUM] python3.4, python3.5 vulnerabilities
python3.4, python3.5 vulnerabilities
It was discovered that Python incorrectly handled certain RFCs.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 16.04 ESM. (CVE-2021-3733)
It was discovered that Python incorrectly handled certain
server responses. An attacker could possibly use this issue to
cause a denial of service. (CVE-2021-3737)
Ubuntu
Python vulnerabilities
vendor_ubuntu·2024-07-11·CVSS 7.6
CVE-2021-29921 [HIGH] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that Python incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.
(CVE-2015-20107)
It was discovered that Python incorrectly used regular expressions
vulnerable to catastrophic backtracking. A remote attacker could possibly
use this issue to cause a denial of service. This issue only affected
Ubuntu 14.04 LTS. (CVE-2018-1060, CVE-2018-1061)
It was discovered that Python failed to initialize Expat’s hash salt. A
remote attacker could possibly use this issue to cause hash collisions,
leading to a denial of service. This issue only affected Ubuntu 14.04 LTS.
(CVE-2018-14647)
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle Database - Machine Learning for Python (Python) — CVE-2021-3737
vendor_oracle·2023-01-15·CVSS 6.5
CVE-2021-3737 [HIGH] Oracle Oracle Database Server Risk Matrix: Oracle Database - Machine Learning for Python (Python) — CVE-2021-3737
Oracle Oracle Database Server Risk Matrix: Oracle Database - Machine Learning for Python (Python) vulnerability
CVE: CVE-2021-3737
CVSS: 6.5
Protocol: Oracle Net
Remote exploit: No
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Microsoft
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker who controls the HTTP server to make the client script enter an infinite l
vendor_msrc·2022-03-08·CVSS 7.5
CVE-2021-3737 [HIGH] CWE-400 A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker who controls the HTTP server to make the client script enter an infinite l
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker who controls the HTTP server to make the client script enter an infinite loop consuming CPU time. The highest threat from this vulnerability is to system availability.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog
Ubuntu
Python vulnerabilities
vendor_ubuntu·2021-12-17·CVSS 6.5
CVE-2021-3737 [MEDIUM] Python vulnerabilities
Title: Python vulnerabilities
Summary: Python could be made to crash if it receives specially crafted input from a malicious server.
It was discovered that the urllib.request.AbstractBasicAuthHandler class
in Python contains regex with a quadratic worst-case time complexity.
Specially crafted traffic from a malicious HTTP server could cause a regular
expression denial of service (ReDoS) condition for a client.
(CVE-2021-3733)
It was discovered that the Python urllib http client could enter into an infinite
loop when incorrectly handling certain server responses (100 Continue response).
Specially crafted traffic from a malicious HTTP server could cause a denial of
service (DoS) condition for a client.
(CVE-2021-3737)
Instructions: In general, a standard system update will make all the n
Ubuntu
Python vulnerabilities
vendor_ubuntu·2021-12-17·CVSS 6.5
CVE-2021-3737 [MEDIUM] Python vulnerabilities
Title: Python vulnerabilities
Summary: Python could be made to crash if it receives specially crafted input from a malicious server.
It was discovered that the urllib.request.AbstractBasicAuthHandler class
in Python contains regex allowing for catastrophic backtracking. Specially
crafted traffic from a malicious HTTP server could cause a regular expression
denial of service (ReDoS) condition for a client.
(CVE-2020-8492)
It was discovered that the urllib.request.AbstractBasicAuthHandler class
in Python contains regex with a quadratic worst-case time complexity.
Specially crafted traffic from a malicious HTTP server could cause a regular
expression denial of service (ReDoS) condition for a client.
(CVE-2021-3733)
It was discovered that the Python urllib http client could enter into an i
Ubuntu
Python vulnerabilities
vendor_ubuntu·2021-12-17
CVE-2021-3737 Python vulnerabilities
Title: Python vulnerabilities
Summary: Python could be made to crash if it receives specially crafted input from a malicious server.
It was discovered that the Python urllib http client could enter into an infinite
loop when incorrectly handling certain server responses (100 Continue response).
Specially crafted traffic from a malicious HTTP server could cause a denial of
service (Dos) condition for a client.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Python vulnerabilities
vendor_ubuntu·2021-09-16·CVSS 6.5
CVE-2021-3733 [MEDIUM] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that Python incorrectly handled certain RFCs.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 16.04 ESM. (CVE-2021-3733)
It was discovered that Python incorrectly handled certain
server responses. An attacker could possibly use this issue to
cause a denial of service. (CVE-2021-3737)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python: urllib: HTTP client possible infinite loop on a 100 Continue response
vendor_redhat·2021-08-09·CVSS 7.5
CVE-2021-3737 [HIGH] CWE-835 python: urllib: HTTP client possible infinite loop on a 100 Continue response
python: urllib: HTTP client possible infinite loop on a 100 Continue response
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.
Statement: Given the flaw is in the client side and it requires automatically connecting to a compromised but trusted server
Debian
CVE-2021-3737: pypy3 - A flaw was found in python. An improperly handled HTTP response in the HTTP clie...
vendor_debian·2021·CVSS 7.5
CVE-2021-3737 [HIGH] CVE-2021-3737: pypy3 - A flaw was found in python. An improperly handled HTTP response in the HTTP clie...
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.
Scope: local
bookworm: resolved (fixed in 7.3.8+dfsg-1)
bullseye: resolved (fixed in 7.3.5+dfsg-2+deb11u4)
forky: resolved (fixed in 7.3.8+dfsg-1)
sid: resolved (fixed in 7.3.8+dfsg-1)
trixie: resolved (fixed in 7.3.8+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.python.org/issue44022https://bugzilla.redhat.com/show_bug.cgi?id=1995162https://github.com/python/cpython/pull/25916https://github.com/python/cpython/pull/26503https://lists.debian.org/debian-lts-announce/2023/05/msg00024.htmlhttps://lists.debian.org/debian-lts-announce/2023/06/msg00039.htmlhttps://python-security.readthedocs.io/vuln/urllib-100-continue-loop.htmlhttps://security.netapp.com/advisory/ntap-20220407-0009/https://ubuntu.com/security/CVE-2021-3737https://www.oracle.com/security-alerts/cpujul2022.htmlhttps://bugs.python.org/issue44022https://bugzilla.redhat.com/show_bug.cgi?id=1995162https://github.com/python/cpython/pull/25916https://github.com/python/cpython/pull/26503https://lists.debian.org/debian-lts-announce/2023/05/msg00024.htmlhttps://lists.debian.org/debian-lts-announce/2023/06/msg00039.htmlhttps://lists.debian.org/debian-lts-announce/2024/11/msg00024.htmlhttps://lists.debian.org/debian-lts-announce/2024/12/msg00000.htmlhttps://python-security.readthedocs.io/vuln/urllib-100-continue-loop.htmlhttps://security.netapp.com/advisory/ntap-20220407-0009/https://ubuntu.com/security/CVE-2021-3737https://www.oracle.com/security-alerts/cpujul2022.html
2022-03-04
Published