← Back to CVE List
Vulnerability Intelligence Report

CVE-2021-29921

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:6.83%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Affected Products & Versions

Vendor Product Affected Versions
python python all
oracle communications_cloud_native_core_automated_test_suite 1.8.0
oracle communications_cloud_native_core_binding_support_function 1.11.0
oracle communications_cloud_native_core_network_slice_selection_function 1.8.0
oracle graalvm 20.3.2, 21.1.0
oracle zfs_storage_appliance_kit 8.8

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
6.827%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2021-04-01T00:00:00
Published2021-05-06T00:00:00
Last Updated2025-11-03T21:44:43

LINK COPIED TO CLIPBOARD