---
id: CVE-2021-3733
title: There's a flaw in urllib's AbstractBasicAuthHandler class
summary: >-
  There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who
  controls a malicious HTTP server that an HTTP client (such as web browser)
  connects to, could trigger a Regular Expression Denial of Service (ReDOS)
  during an aut…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
  - CWE-400
vendor: python
product: python
affected:
  - python < 3.6.14
  - 'python >= 3.7.0, < 3.7.11'
  - 'python >= 3.8.0, < 3.8.10'
  - 'python >= 3.9.0, < 3.9.5'
  - python = 3.10.0
  - codeready_linux_builder = 8.0
  - codeready_linux_builder_for_ibm_z_systems = 8.0
  - codeready_linux_builder_for_power_little_endian = 8.0
  - enterprise_linux = 8.0
  - enterprise_linux_eus = 8.4
  - enterprise_linux_for_ibm_z_systems = 8.0
  - enterprise_linux_for_ibm_z_systems_eus = 8.4
  - enterprise_linux_for_power_little_endian = 8.0
  - enterprise_linux_for_power_little_endian_eus = 8.4
  - enterprise_linux_server_aus = 8.4
  - >-
    enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions
    = 8.4
  - enterprise_linux_server_tus = 8.4
  - enterprise_linux_server_update_services_for_sap_solutions = 8.4
  - extra_packages_for_enterprise_linux = 7.0
  - fedora = 33
  - fedora = 34
  - fedora = 35
  - fedora = 36
  - management_services_for_element_software_and_netapp_hci
  - ontap_select_deploy_administration_utility
  - 'solidfire,_enterprise_sds_&_hci_storage_node'
  - hci_compute_node_firmware
patched:
  - python 3.9.5
published: '2022-03-10'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:41.183'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-3733'
references:
  - url: 'https://bugs.python.org/issue43075'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1995234'
    label: secalert@redhat.com
  - url: >-
      https://github.com/python/cpython/commit/7215d1ae25525c92b026166f9d5cac85fb
    label: secalert@redhat.com
  - url: 'https://github.com/python/cpython/pull/24391'
    label: secalert@redhat.com
  - url: 'https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html'
    label: secalert@redhat.com
  - url: 'https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html'
    label: secalert@redhat.com
  - url: 'https://security.netapp.com/advisory/ntap-20220407-0001/'
    label: secalert@redhat.com
  - url: 'https://ubuntu.com/security/CVE-2021-3733'
    label: secalert@redhat.com
  - url: 'https://bugs.python.org/issue43075'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1995234'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/python/cpython/commit/7215d1ae25525c92b026166f9d5cac85fb
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/python/cpython/pull/24391'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20220407-0001/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://ubuntu.com/security/CVE-2021-3733'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.04675
epssPercentile: 0.91526
ingestedAt: '2026-10-08T22:11:53.747Z'
---

## Overview

There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.

## Affected

- `python < 3.6.14`
- `python >= 3.7.0, < 3.7.11`
- `python >= 3.8.0, < 3.8.10`
- `python >= 3.9.0, < 3.9.5`
- `python = 3.10.0`
- `codeready_linux_builder = 8.0`
- `codeready_linux_builder_for_ibm_z_systems = 8.0`
- `codeready_linux_builder_for_power_little_endian = 8.0`
- `enterprise_linux = 8.0`
- `enterprise_linux_eus = 8.4`
- `enterprise_linux_for_ibm_z_systems = 8.0`
- `enterprise_linux_for_ibm_z_systems_eus = 8.4`
- `enterprise_linux_for_power_little_endian = 8.0`
- `enterprise_linux_for_power_little_endian_eus = 8.4`
- `enterprise_linux_server_aus = 8.4`
- `enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.4`
- `enterprise_linux_server_tus = 8.4`
- `enterprise_linux_server_update_services_for_sap_solutions = 8.4`
- `extra_packages_for_enterprise_linux = 7.0`
- `fedora = 33`
- `fedora = 34`
- `fedora = 35`
- `fedora = 36`
- `management_services_for_element_software_and_netapp_hci`
- `ontap_select_deploy_administration_utility`
- `solidfire,_enterprise_sds_&_hci_storage_node`
- `hci_compute_node_firmware`

## Remediation

Upgrade past the affected range:

- `python 3.9.5`
