{"id":"CVE-2021-3733","title":"There's a flaw in urllib's AbstractBasicAuthHandler class","summary":"There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an aut…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-400","CWE-400"],"vendor":"python","product":"python","affected":["python < 3.6.14","python >= 3.7.0, < 3.7.11","python >= 3.8.0, < 3.8.10","python >= 3.9.0, < 3.9.5","python = 3.10.0","codeready_linux_builder = 8.0","codeready_linux_builder_for_ibm_z_systems = 8.0","codeready_linux_builder_for_power_little_endian = 8.0","enterprise_linux = 8.0","enterprise_linux_eus = 8.4","enterprise_linux_for_ibm_z_systems = 8.0","enterprise_linux_for_ibm_z_systems_eus = 8.4","enterprise_linux_for_power_little_endian = 8.0","enterprise_linux_for_power_little_endian_eus = 8.4","enterprise_linux_server_aus = 8.4","enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.4","enterprise_linux_server_tus = 8.4","enterprise_linux_server_update_services_for_sap_solutions = 8.4","extra_packages_for_enterprise_linux = 7.0","fedora = 33","fedora = 34","fedora = 35","fedora = 36","management_services_for_element_software_and_netapp_hci","ontap_select_deploy_administration_utility","solidfire,_enterprise_sds_&_hci_storage_node","hci_compute_node_firmware"],"patched":["python 3.9.5"],"published":"2022-03-10","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:17:41.183","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-3733","references":[{"url":"https://bugs.python.org/issue43075","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1995234","label":"secalert@redhat.com"},{"url":"https://github.com/python/cpython/commit/7215d1ae25525c92b026166f9d5cac85fb","label":"secalert@redhat.com"},{"url":"https://github.com/python/cpython/pull/24391","label":"secalert@redhat.com"},{"url":"https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","label":"secalert@redhat.com"},{"url":"https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html","label":"secalert@redhat.com"},{"url":"https://security.netapp.com/advisory/ntap-20220407-0001/","label":"secalert@redhat.com"},{"url":"https://ubuntu.com/security/CVE-2021-3733","label":"secalert@redhat.com"},{"url":"https://bugs.python.org/issue43075","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1995234","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/python/cpython/commit/7215d1ae25525c92b026166f9d5cac85fb","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/python/cpython/pull/24391","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20220407-0001/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://ubuntu.com/security/CVE-2021-3733","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.04675,"epssPercentile":0.91526,"ingestedAt":"2026-10-08T22:11:53.747Z","slug":"CVE-2021-3733","body":"## Overview\n\nThere's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.\n\n## Affected\n\n- `python < 3.6.14`\n- `python >= 3.7.0, < 3.7.11`\n- `python >= 3.8.0, < 3.8.10`\n- `python >= 3.9.0, < 3.9.5`\n- `python = 3.10.0`\n- `codeready_linux_builder = 8.0`\n- `codeready_linux_builder_for_ibm_z_systems = 8.0`\n- `codeready_linux_builder_for_power_little_endian = 8.0`\n- `enterprise_linux = 8.0`\n- `enterprise_linux_eus = 8.4`\n- `enterprise_linux_for_ibm_z_systems = 8.0`\n- `enterprise_linux_for_ibm_z_systems_eus = 8.4`\n- `enterprise_linux_for_power_little_endian = 8.0`\n- `enterprise_linux_for_power_little_endian_eus = 8.4`\n- `enterprise_linux_server_aus = 8.4`\n- `enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.4`\n- `enterprise_linux_server_tus = 8.4`\n- `enterprise_linux_server_update_services_for_sap_solutions = 8.4`\n- `extra_packages_for_enterprise_linux = 7.0`\n- `fedora = 33`\n- `fedora = 34`\n- `fedora = 35`\n- `fedora = 36`\n- `management_services_for_element_software_and_netapp_hci`\n- `ontap_select_deploy_administration_utility`\n- `solidfire,_enterprise_sds_&_hci_storage_node`\n- `hci_compute_node_firmware`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `python 3.9.5`","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":35.8,"likelihood":0.9,"exploitation":0,"ransomware":0},"changes":[]}