---
id: CVE-2021-29921
title: >-
  In Python before 3,9,5, the ipaddress library mishandles leading zero
  characters in the octets of an IP address string
summary: >-
  In Python before 3,9,5, the ipaddress library mishandles leading zero
  characters in the octets of an IP address string. This (in some situations)
  allows attackers to bypass access control that is based on IP addresses.
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: python
product: python
affected:
  - 'python >= 3.8.0, < 3.8.12'
  - 'python >= 3.9.0, < 3.9.5'
  - communications_cloud_native_core_automated_test_suite = 1.8.0
  - communications_cloud_native_core_binding_support_function = 1.11.0
  - communications_cloud_native_core_network_slice_selection_function = 1.8.0
  - graalvm = 20.3.2
  - graalvm = 21.1.0
  - zfs_storage_appliance_kit = 8.8
patched:
  - python 3.9.5
published: '2021-05-06'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:17:09.223'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-29921'
references:
  - url: 'https://bugs.python.org/issue36384'
    label: cve@mitre.org
  - url: 'https://docs.python.org/3/library/ipaddress.html'
    label: cve@mitre.org
  - url: >-
      https://github.com/python/cpython/blob/63298930fb531ba2bb4f23bc3b915dbf1e17e9e1/Misc/NEWS.d/3.8.0a4.rst
    label: cve@mitre.org
  - url: 'https://github.com/python/cpython/pull/12577'
    label: cve@mitre.org
  - url: 'https://github.com/python/cpython/pull/25099'
    label: cve@mitre.org
  - url: 'https://github.com/sickcodes'
    label: cve@mitre.org
  - url: >-
      https://github.com/sickcodes/security/blob/master/advisories/SICK-2021-014.md
    label: cve@mitre.org
  - url: >-
      https://python-security.readthedocs.io/vuln/ipaddress-ipv4-leading-zeros.html
    label: cve@mitre.org
  - url: 'https://security.gentoo.org/glsa/202305-02'
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20210622-0003/'
    label: cve@mitre.org
  - url: 'https://sick.codes/sick-2021-014'
    label: cve@mitre.org
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: cve@mitre.org
  - url: 'https://bugs.python.org/issue36384'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://docs.python.org/3/library/ipaddress.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/python/cpython/blob/63298930fb531ba2bb4f23bc3b915dbf1e17e9e1/Misc/NEWS.d/3.8.0a4.rst
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/python/cpython/pull/12577'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/python/cpython/pull/25099'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/sickcodes'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/sickcodes/security/blob/master/advisories/SICK-2021-014.md
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://python-security.readthedocs.io/vuln/ipaddress-ipv4-leading-zeros.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202305-02'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20210622-0003/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://sick.codes/sick-2021-014'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujan2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.06882
epssPercentile: 0.93905
ingestedAt: '2026-10-08T23:16:47.319Z'
---

## Overview

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

## Affected

- `python >= 3.8.0, < 3.8.12`
- `python >= 3.9.0, < 3.9.5`
- `communications_cloud_native_core_automated_test_suite = 1.8.0`
- `communications_cloud_native_core_binding_support_function = 1.11.0`
- `communications_cloud_native_core_network_slice_selection_function = 1.8.0`
- `graalvm = 20.3.2`
- `graalvm = 21.1.0`
- `zfs_storage_appliance_kit = 8.8`

## Remediation

Upgrade past the affected range:

- `python 3.9.5`
