CVE-2021-33503: High severity Python urllib3 vulnerability

Published Jun 1, 2021
·
Updated

Impact

When provided with a URL containing many @ characters in the authority component the authority regular expression exhibits catastrophic backtracking causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.

Patches

The issue has been fixed in urllib3 v1.26.5.

References

- CVE-2021-33503 - JVNVU#92413403 (English) - JVNVU#92413403 (Japanese) - urllib3 v1.26.5

For more information If you have any questions or comments about this advisory: Ask in our community Discord Email sethmichaellarson@gmail.com

Other sources

A flaw was found in python-urllib3. When provided with a URL containing many @ characters in the authority component, the authority's regular expression exhibits catastrophic backtracking. This flaw causes a denial of service if a URL is passed as a parameter or redirected via an HTTP redirect. The highest threat from this vulnerability is to system availability.

An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component the authority regular expression exhibits catastrophic backtracking causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.

Microsoft

An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.

urllib3 is vulnerable to a denial of service, caused by a regular expression denial of service (ReDoS) flaw due to catastrophic backtracking. By sending a specially-crafted URL request, a remote attacker could exploit this vulnerability to cause a denial of service condition.

IBM

When provided with a URL containing many @ characters in the authority component the authority regular expression exhibits catastrophic backtracking causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.

References:

https://github.com/advisories/GHSA-q2q7-5pp4-w6pg

Red Hat

Affected Software

38 affected componentsFixes available
redhat/automation-hub<0:4.2.6-1.el7
0:4.2.6-1.el7
redhat/python3-chardet<0:3.0.4-3.el7
0:3.0.4-3.el7
redhat/python3-click<0:7.1.2-3.el7
0:7.1.2-3.el7
redhat/python3-gnupg<0:0.4.6-3.el7
0:0.4.6-3.el7
redhat/python3-jinja2<0:2.11.2-3.el7
0:2.11.2-3.el7
redhat/python3-markupsafe<0:1.1.1-4.el7
0:1.1.1-4.el7
redhat/python3-semantic-version<0:2.8.5-3.el7
0:2.8.5-3.el7
redhat/python-galaxy-ng<0:4.2.6-1.el7
0:4.2.6-1.el7
redhat/python-requests<0:2.25.1-1.el7
0:2.25.1-1.el7
redhat/python-urllib3<0:1.26.5-1.el7
0:1.26.5-1.el7
redhat/automation-hub<0:4.2.6-1.el8
0:4.2.6-1.el8
redhat/python3-click<0:7.1.2-3.el8
0:7.1.2-3.el8
redhat/python3-gnupg<0:0.4.6-3.el8
0:0.4.6-3.el8
redhat/python3-jinja2<0:2.11.2-3.el8
0:2.11.2-3.el8
redhat/python3-markupsafe<0:1.1.1-4.el8
0:1.1.1-4.el8
redhat/python3-semantic-version<0:2.8.5-3.el8
0:2.8.5-3.el8
redhat/python-galaxy-ng<0:4.2.6-1.el8
0:4.2.6-1.el8
redhat/python-requests<0:2.25.1-1.el8
0:2.25.1-1.el8
redhat/python-urllib3<0:1.26.5-1.el8
0:1.26.5-1.el8
redhat/rh-python38-babel<0:2.7.0-12.el7
0:2.7.0-12.el7
redhat/rh-python38-python<0:3.8.11-2.el7
0:3.8.11-2.el7
redhat/rh-python38-python-cryptography<0:2.8-5.el7
0:2.8-5.el7
redhat/rh-python38-python-jinja2<0:2.10.3-6.el7
0:2.10.3-6.el7
redhat/rh-python38-python-lxml<0:4.4.1-7.el7
0:4.4.1-7.el7
redhat/rh-python38-python-pip<0:19.3.1-2.el7
0:19.3.1-2.el7
redhat/rh-python38-python-urllib3<0:1.25.7-7.el7
0:1.25.7-7.el7
pip/urllib3>=1.25.4<1.26.5
1.26.5
Python urllib3>=1.25.4<1.26.5
Fedoraproject Fedora=33
Fedoraproject Fedora=34
Oracle Enterprise Manager Ops Center=12.4.0.0
Oracle Instantis Enterprisetrack=17.1
Oracle Instantis Enterprisetrack=17.2
Oracle Instantis Enterprisetrack=17.3
Oracle ZFS Storage Appliance Kit=8.8
redhat/urllib3<1.26.5
1.26.5
Microsoft cm1 python-urllib3 1.25.9-2
Microsoft cbl2 python-urllib3 1.25.9-3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/automation-hub to a version that resolves this vulnerability.

    Fixed in 0:4.2.6-1.el7
  2. Upgrade

    Upgrade redhat/python3-chardet to a version that resolves this vulnerability.

    Fixed in 0:3.0.4-3.el7
  3. Upgrade

    Upgrade redhat/python3-click to a version that resolves this vulnerability.

    Fixed in 0:7.1.2-3.el7
  4. Upgrade

    Upgrade redhat/python3-gnupg to a version that resolves this vulnerability.

    Fixed in 0:0.4.6-3.el7
  5. Upgrade

    Upgrade redhat/python3-jinja2 to a version that resolves this vulnerability.

    Fixed in 0:2.11.2-3.el7
  6. Upgrade

    Upgrade redhat/python3-markupsafe to a version that resolves this vulnerability.

    Fixed in 0:1.1.1-4.el7
  7. Upgrade

    Upgrade redhat/python3-semantic-version to a version that resolves this vulnerability.

    Fixed in 0:2.8.5-3.el7
  8. Upgrade

    Upgrade redhat/python-galaxy-ng to a version that resolves this vulnerability.

    Fixed in 0:4.2.6-1.el7
  9. Upgrade

    Upgrade redhat/python-requests to a version that resolves this vulnerability.

    Fixed in 0:2.25.1-1.el7
  10. Upgrade

    Upgrade redhat/python-urllib3 to a version that resolves this vulnerability.

    Fixed in 0:1.26.5-1.el7
  11. Upgrade

    Upgrade redhat/automation-hub to a version that resolves this vulnerability.

    Fixed in 0:4.2.6-1.el8
  12. Upgrade

    Upgrade redhat/python3-click to a version that resolves this vulnerability.

    Fixed in 0:7.1.2-3.el8
  13. Upgrade

    Upgrade redhat/python3-gnupg to a version that resolves this vulnerability.

    Fixed in 0:0.4.6-3.el8
  14. Upgrade

    Upgrade redhat/python3-jinja2 to a version that resolves this vulnerability.

    Fixed in 0:2.11.2-3.el8
  15. Upgrade

    Upgrade redhat/python3-markupsafe to a version that resolves this vulnerability.

    Fixed in 0:1.1.1-4.el8
  16. Upgrade

    Upgrade redhat/python3-semantic-version to a version that resolves this vulnerability.

    Fixed in 0:2.8.5-3.el8
  17. Upgrade

    Upgrade redhat/python-galaxy-ng to a version that resolves this vulnerability.

    Fixed in 0:4.2.6-1.el8
  18. Upgrade

    Upgrade redhat/python-requests to a version that resolves this vulnerability.

    Fixed in 0:2.25.1-1.el8
  19. Upgrade

    Upgrade redhat/python-urllib3 to a version that resolves this vulnerability.

    Fixed in 0:1.26.5-1.el8
  20. Upgrade

    Upgrade redhat/rh-python38-babel to a version that resolves this vulnerability.

    Fixed in 0:2.7.0-12.el7
  21. Upgrade

    Upgrade redhat/rh-python38-python to a version that resolves this vulnerability.

    Fixed in 0:3.8.11-2.el7
  22. Upgrade

    Upgrade redhat/rh-python38-python-cryptography to a version that resolves this vulnerability.

    Fixed in 0:2.8-5.el7
  23. Upgrade

    Upgrade redhat/rh-python38-python-jinja2 to a version that resolves this vulnerability.

    Fixed in 0:2.10.3-6.el7
  24. Upgrade

    Upgrade redhat/rh-python38-python-lxml to a version that resolves this vulnerability.

    Fixed in 0:4.4.1-7.el7
  25. Upgrade

    Upgrade redhat/rh-python38-python-pip to a version that resolves this vulnerability.

    Fixed in 0:19.3.1-2.el7
  26. Upgrade

    Upgrade redhat/rh-python38-python-urllib3 to a version that resolves this vulnerability.

    Fixed in 0:1.25.7-7.el7
  27. Upgrade

    Upgrade pip/urllib3 to a version that resolves this vulnerability.

    Fixed in 1.26.5
  28. Upgrade

    Upgrade redhat/urllib3 to a version that resolves this vulnerability.

    Fixed in 1.26.5

Event History

Jun 1, 2021
CVE Published
12:00 AM
Advisory Published
via GitHub·09:19 PM
Data Sourced
via GitHub·09:19 PM
DescriptionSeverityWeaknessAffected Software
Jun 4, 2021
Data Sourced
via Red Hat·09:09 PM
DescriptionSeverityAffected Software
Jun 29, 2021
CVE Published
via MITRE·10:55 AM
Data Sourced
via MITRE·10:55 AM
Description
Data Sourced
via NVD·11:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jul 3, 2021
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Dec 13, 2023
Data Sourced
via IBM·12:00 AM
DescriptionSeverityAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2021-33503?

CVE-2021-33503 is a vulnerability in urllib3 before version 1.26.5 that allows for denial of service attacks through a regex backtracking issue.

2

What is the impact of CVE-2021-33503?

CVE-2021-33503 can cause a denial of service if a URL with many '@' characters in the authority component is passed as a parameter or redirected to via an HTTP redirect.

3

How severe is CVE-2021-33503?

CVE-2021-33503 has a severity rating of 7.5 (High).

4

How do I fix CVE-2021-33503?

To fix CVE-2021-33503, update urllib3 to version 1.26.5 or apply the patches provided by the respective vendors.

5

Where can I find more information about CVE-2021-33503?

You can find more information about CVE-2021-33503 at the following references: [GitHub Advisory](https://github.com/advisories/GHSA-q2q7-5pp4-w6pg), [urllib3 Commit](https://github.com/urllib3/urllib3/commit/2d4a3fee6de2fa45eb82169361918f759269b4ec), [Fedora Security Announcement](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6SCV7ZNAHS3E6PBFLJGENCDRDRWRZZ6W/)

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203