← Back to CVE List
Vulnerability Intelligence Report

CVE-2021-3733

There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.

No Active Exploit Signals
CVSS Base Score
6.5
MEDIUM
EPSS Probability:4.67%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-400 ↗CWE-400 - Uncontrolled Resource Consumption

Affected Products & Versions

Vendor Product Affected Versions
python python 3.10.0
redhat codeready_linux_builder 8.0
redhat codeready_linux_builder_for_ibm_z_systems 8.0
redhat codeready_linux_builder_for_power_little_endian 8.0
redhat enterprise_linux 8.0
redhat enterprise_linux_eus 8.4
redhat enterprise_linux_for_ibm_z_systems 8.0
redhat enterprise_linux_for_ibm_z_systems_eus 8.4
redhat enterprise_linux_for_power_little_endian 8.0
redhat enterprise_linux_for_power_little_endian_eus 8.4
redhat enterprise_linux_server_aus 8.4
redhat enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions 8.4
redhat enterprise_linux_server_tus 8.4
redhat enterprise_linux_server_update_services_for_sap_solutions 8.4
fedoraproject extra_packages_for_enterprise_linux 7.0
fedoraproject fedora 33, 34, 35, 36
netapp management_services_for_element_software_and_netapp_hci all
netapp ontap_select_deploy_administration_utility all
netapp solidfire\,_enterprise_sds_\&_hci_storage_node all
netapp hci_compute_node_firmware all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
4.675%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityRed Hat, Inc. · Vendor · USA
Reserved2021-08-23T00:00:00
Published2022-03-07T00:00:00
Last Updated2025-11-03T21:45:06

LINK COPIED TO CLIPBOARD