CVE-2021-33503High· 7.5▾ TwilightCatastrophic backtracking in URL authority parser when passed URL containing many @ characters
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.7 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
3.3%
When provided with a URL containing many @ characters in the authority component the authority regular expression exhibits catastrophic backtracking causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.
The issue has been fixed in urllib3 v1.26.5.
If you have any questions or comments about this advisory:
urllib3 >= 1.25.4, < 1.26.5Upgrade to a patched release:
urllib3 1.26.5Connected by shared product, vendor, weakness, or advisory.
CVE-2021-28363Medium· 6.5Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection
CVE-2023-43804Medium· 5.9`Cookie` HTTP header isn't stripped on cross-origin redirects
CVE-2023-45803Medium· 4.2urllib3's request body not stripped after redirect from 303 status changes request method to GET
CVE-2025-66418Highurllib3 allows an unbounded number of links in the decompression chain
CVE-2024-37891Medium· 4.4urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects
CVE-2025-66471Highurllib3 streaming API improperly handles highly compressed data