CVE-2020-7212: High severity Python urllib3 vulnerability
The encodeinvalidchars function in util/url.py in the urllib3 library 1.25.2 through 1.25.7 for Python allows a denial of service (CPU consumption) because of an inefficient algorithm. The percentencodings array contains all matches of percent encodings. It is not deduplicated. For a URL of length N, the size of percentencodings may be up to O(N). The next step (normalize existing percent-encoded bytes) also takes up to O(N) for each step, so the total time is O(N^2). If percentencodings were deduplicated, the time to compute encodeinvalidchars would be O(kN), where k is at most 484 ((10+62)^2).
Other sources
urllib3 is vulnerable to a denial of service, caused by a flaw in the encodeinvalidchars function in util/url.py. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/urllib3to a version that resolves this vulnerability.Fixed in 1.25.8
Event History
Frequently Asked Questions
What is CVE-2020-7212?
CVE-2020-7212 is a vulnerability in the urllib3 library for Python that allows a denial of service (CPU consumption) due to an inefficient algorithm in the _encode_invalid_chars function.
How severe is CVE-2020-7212?
CVE-2020-7212 has a severity rating of 7.5 (high).
Which software is affected by CVE-2020-7212?
The urllib3 library versions 1.25.2 through 1.25.7 for Python are affected by CVE-2020-7212.
How can I fix CVE-2020-7212?
To fix CVE-2020-7212, upgrade to urllib3 version 1.25.8 or later.
Where can I find more information about CVE-2020-7212?
You can find more information about CVE-2020-7212 in the references provided: [link1], [link2], [link3].