CVE-2021-29921Critical· 9.8▾ MidnightIn Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 1.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
6.9%
In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.
python >= 3.8.0, < 3.8.12python >= 3.9.0, < 3.9.5communications_cloud_native_core_automated_test_suite = 1.8.0communications_cloud_native_core_binding_support_function = 1.11.0communications_cloud_native_core_network_slice_selection_function = 1.8.0graalvm = 20.3.2graalvm = 21.1.0zfs_storage_appliance_kit = 8.8Upgrade past the affected range:
python 3.9.5Connected by shared product, vendor, weakness, or advisory.
CVE-2015-20107High· 7.6In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file
CVE-2020-27619Critical· 9.8In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.
CVE-2020-26116High· 7.2http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in…
CVE-2019-9636Critical· 9.8Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization
CVE-2019-9740Medium· 6.1An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3
CVE-2021-3733Medium· 6.5There's a flaw in urllib's AbstractBasicAuthHandler class