There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.
AI analysis not yet available
Plain-English explanation, risk summary, and remediation steps will appear here once AI analysis is complete.
No Fix Known
No patch has been released yet. Apply workarounds or mitigations where available.
Published
CVE disclosed publicly
Last Modified
Most recent update
Indexed to CVEInsight
Added to this platform
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
27
Affected Products
17
References
python / python
| - |
| python | python | 3.9.0 - 3.9.5 | - |
| python | python | - | - |
| redhat | codeready_linux_builder | - | - |
| redhat | codeready_linux_builder_for_ibm_z_systems | - | - |
| redhat | codeready_linux_builder_for_power_little_endian | - | - |
| redhat | enterprise_linux | - | - |
| redhat | enterprise_linux_eus | - | - |
| redhat | enterprise_linux_for_ibm_z_systems | - | - |
| redhat | enterprise_linux_for_ibm_z_systems_eus | - | - |
| redhat | enterprise_linux_for_power_little_endian | - | - |
| redhat | enterprise_linux_for_power_little_endian_eus | - | - |
| redhat | enterprise_linux_server_aus | - | - |
| redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions | - | - |
| redhat | enterprise_linux_server_tus | - | - |
| redhat | enterprise_linux_server_update_services_for_sap_solutions | - | - |
| fedoraproject | extra_packages_for_enterprise_linux | - | - |
| fedoraproject | fedora | - | - |
| fedoraproject | fedora | - | - |
| fedoraproject | fedora | - | - |
| fedoraproject | fedora | - | - |
| netapp | management_services_for_element_software_and_netapp_hci | - | - |
| netapp | ontap_select_deploy_administration_utility | - | - |
| netapp | solidfire\,_enterprise_sds_\&_hci_storage_node | - | - |
| netapp | hci_compute_node_firmware | - | - |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability
Impact