CVE-2021-33503: High severity Python urllib3 vulnerability
Impact
When provided with a URL containing many @ characters in the authority component the authority regular expression exhibits catastrophic backtracking causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.
Patches
The issue has been fixed in urllib3 v1.26.5.
References
- CVE-2021-33503 - JVNVU#92413403 (English) - JVNVU#92413403 (Japanese) - urllib3 v1.26.5
For more information If you have any questions or comments about this advisory: Ask in our community Discord Email sethmichaellarson@gmail.com
Other sources
A flaw was found in python-urllib3. When provided with a URL containing many @ characters in the authority component, the authority's regular expression exhibits catastrophic backtracking. This flaw causes a denial of service if a URL is passed as a parameter or redirected via an HTTP redirect. The highest threat from this vulnerability is to system availability.
An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component the authority regular expression exhibits catastrophic backtracking causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.
— Microsoft
An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.
urllib3 is vulnerable to a denial of service, caused by a regular expression denial of service (ReDoS) flaw due to catastrophic backtracking. By sending a specially-crafted URL request, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
When provided with a URL containing many @ characters in the authority component the authority regular expression exhibits catastrophic backtracking causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.
References:
https://github.com/advisories/GHSA-q2q7-5pp4-w6pg
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/automation-hubto a version that resolves this vulnerability.Fixed in 0:4.2.6-1.el7 - Upgrade
Upgrade
redhat/python3-chardetto a version that resolves this vulnerability.Fixed in 0:3.0.4-3.el7 - Upgrade
Upgrade
redhat/python3-clickto a version that resolves this vulnerability.Fixed in 0:7.1.2-3.el7 - Upgrade
Upgrade
redhat/python3-gnupgto a version that resolves this vulnerability.Fixed in 0:0.4.6-3.el7 - Upgrade
Upgrade
redhat/python3-jinja2to a version that resolves this vulnerability.Fixed in 0:2.11.2-3.el7 - Upgrade
Upgrade
redhat/python3-markupsafeto a version that resolves this vulnerability.Fixed in 0:1.1.1-4.el7 - Upgrade
Upgrade
redhat/python3-semantic-versionto a version that resolves this vulnerability.Fixed in 0:2.8.5-3.el7 - Upgrade
Upgrade
redhat/python-galaxy-ngto a version that resolves this vulnerability.Fixed in 0:4.2.6-1.el7 - Upgrade
Upgrade
redhat/python-requeststo a version that resolves this vulnerability.Fixed in 0:2.25.1-1.el7 - Upgrade
Upgrade
redhat/python-urllib3to a version that resolves this vulnerability.Fixed in 0:1.26.5-1.el7 - Upgrade
Upgrade
redhat/automation-hubto a version that resolves this vulnerability.Fixed in 0:4.2.6-1.el8 - Upgrade
Upgrade
redhat/python3-clickto a version that resolves this vulnerability.Fixed in 0:7.1.2-3.el8 - Upgrade
Upgrade
redhat/python3-gnupgto a version that resolves this vulnerability.Fixed in 0:0.4.6-3.el8 - Upgrade
Upgrade
redhat/python3-jinja2to a version that resolves this vulnerability.Fixed in 0:2.11.2-3.el8 - Upgrade
Upgrade
redhat/python3-markupsafeto a version that resolves this vulnerability.Fixed in 0:1.1.1-4.el8 - Upgrade
Upgrade
redhat/python3-semantic-versionto a version that resolves this vulnerability.Fixed in 0:2.8.5-3.el8 - Upgrade
Upgrade
redhat/python-galaxy-ngto a version that resolves this vulnerability.Fixed in 0:4.2.6-1.el8 - Upgrade
Upgrade
redhat/python-requeststo a version that resolves this vulnerability.Fixed in 0:2.25.1-1.el8 - Upgrade
Upgrade
redhat/python-urllib3to a version that resolves this vulnerability.Fixed in 0:1.26.5-1.el8 - Upgrade
Upgrade
redhat/rh-python38-babelto a version that resolves this vulnerability.Fixed in 0:2.7.0-12.el7 - Upgrade
Upgrade
redhat/rh-python38-pythonto a version that resolves this vulnerability.Fixed in 0:3.8.11-2.el7 - Upgrade
Upgrade
redhat/rh-python38-python-cryptographyto a version that resolves this vulnerability.Fixed in 0:2.8-5.el7 - Upgrade
Upgrade
redhat/rh-python38-python-jinja2to a version that resolves this vulnerability.Fixed in 0:2.10.3-6.el7 - Upgrade
Upgrade
redhat/rh-python38-python-lxmlto a version that resolves this vulnerability.Fixed in 0:4.4.1-7.el7 - Upgrade
Upgrade
redhat/rh-python38-python-pipto a version that resolves this vulnerability.Fixed in 0:19.3.1-2.el7 - Upgrade
Upgrade
redhat/rh-python38-python-urllib3to a version that resolves this vulnerability.Fixed in 0:1.25.7-7.el7 - Upgrade
Upgrade
pip/urllib3to a version that resolves this vulnerability.Fixed in 1.26.5 - Upgrade
Upgrade
redhat/urllib3to a version that resolves this vulnerability.Fixed in 1.26.5
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-33503?
CVE-2021-33503 is a vulnerability in urllib3 before version 1.26.5 that allows for denial of service attacks through a regex backtracking issue.
What is the impact of CVE-2021-33503?
CVE-2021-33503 can cause a denial of service if a URL with many '@' characters in the authority component is passed as a parameter or redirected to via an HTTP redirect.
How severe is CVE-2021-33503?
CVE-2021-33503 has a severity rating of 7.5 (High).
How do I fix CVE-2021-33503?
To fix CVE-2021-33503, update urllib3 to version 1.26.5 or apply the patches provided by the respective vendors.
Where can I find more information about CVE-2021-33503?
You can find more information about CVE-2021-33503 at the following references: [GitHub Advisory](https://github.com/advisories/GHSA-q2q7-5pp4-w6pg), [urllib3 Commit](https://github.com/urllib3/urllib3/commit/2d4a3fee6de2fa45eb82169361918f759269b4ec), [Fedora Security Announcement](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6SCV7ZNAHS3E6PBFLJGENCDRDRWRZZ6W/)