An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.
2021-06-29T11:15:07.847
2024-11-21T06:08:58.030
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | python | urllib3 | < 1.26.5 | Yes |
Operating System | fedoraproject | fedora | 33 | Yes |
Operating System | fedoraproject | fedora | 34 | Yes |
Application | oracle | enterprise_manager_ops_center | 12.4.0.0 | Yes |
Application | oracle | instantis_enterprisetrack | 17.1 | Yes |
Application | oracle | instantis_enterprisetrack | 17.2 | Yes |
Application | oracle | instantis_enterprisetrack | 17.3 | Yes |
Application | oracle | zfs_storage_appliance_kit | 8.8 | Yes |