View all vulnerabilities

CVE-2021-33503

An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.

Patch Available

Fix available through Seal Security. No upgrade required, protect your application instantly.

Fix without upgrading
Vulnerability Details
Score
Score Vector
Affected Versions
urllib3 < 2d4a3fee6de2fa45eb82169361918f759269b4ec; urllib3 < 1.26.5
Severity
Ecosystem
Python
Publish Date
June 29, 2021
Modified Date
November 7, 2023