Back

MEDIUM

python: urllib: Regular expression DoS in AbstractBasicAuthHandler

Published Mar 7, 2022

Description

There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.

Affected products

Remediation

Red Hat statement

Applications that use AbstractBasicAuthHandler, HTTPBasicAuthHandler and ProxyBasicAuthHandler may be affected by this flaw. Other classes may use the vulnerable method http_error_auth_reqed in AbstractBasicAuthHandler as well. This flaw is out of support scope for versions of Python shipped in Red Hat Enterprise Linux 7 base OS and Red Hat Enterprise Linux 6. For more information about support life cycles, please see https://access.redhat.com/support/policy/updates/errata/

Metrics

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 7, 2022
Updated Nov 3, 2025
Reserved Aug 23, 2021
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 10, 2021