python: urllib: Regular expression DoS in AbstractBasicAuthHandler
Published Mar 7, 2022
6.5
MEDIUMCVSS 3.1
EPSS 4.67%
Description
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.
Affected products
- Vendor n/a Product Python Defaultn/a
- Version Fixed in python v3.6.14, python v3.7.11, python v3.8.10, python v3.9.5.StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Python | n/a |
|
Configuration 1
Configuration 2
- 8.0
- 8.0
- 8.0
- 8.0
- 8.4
- 8.0
- 8.4
- 8.0
- 8.4
- 8.4
- 8.4
- 8.4
- 8.4
Configuration 3
- 7.0
- 33
- 34
- 35
- 36
Configuration 4
- n/a
- n/a
- n/a
- n/a
No data.
Red Hat Enterprise Linux 8
python27:2.7-8060020220210185952.8cdc2268
Fixed · RHSA-2022:1821
Red Hat Enterprise Linux 8
python3-0:3.6.8-39.el8_4
Fixed · RHSA-2021:4057
Red Hat Enterprise Linux 8
python3-0:3.6.8-39.el8_4
Fixed · RHSA-2021:4057
Red Hat Enterprise Linux 8
python38-devel:3.8-8060020220120164031.5294be16
Fixed · RHSA-2022:1764
Red Hat Enterprise Linux 8
python38:3.8-8060020220120164031.5294be16
Fixed · RHSA-2022:1764
Red Hat Enterprise Linux 8
python39-devel:3.9-8050020210811100211.d428a79b
Fixed · RHSA-2021:4160
Red Hat Enterprise Linux 8
python39:3.9-8050020210811100211.d428a79b
Fixed · RHSA-2021:4160
Red Hat Software Collections for Red Hat Enterprise Linux 7
python27-python-0:2.7.18-4.el7
Fixed · RHSA-2022:1663
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-python38-babel-0:2.7.0-12.el7
Fixed · RHSA-2021:3254
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-python38-python-0:3.8.11-2.el7
Fixed · RHSA-2021:3254
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-python38-python-cryptography-0:2.8-5.el7
Fixed · RHSA-2021:3254
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-python38-python-jinja2-0:2.10.3-6.el7
Fixed · RHSA-2021:3254
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-python38-python-lxml-0:4.4.1-7.el7
Fixed · RHSA-2021:3254
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-python38-python-pip-0:19.3.1-2.el7
Fixed · RHSA-2021:3254
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-python38-python-urllib3-0:1.25.7-7.el7
Fixed · RHSA-2021:3254
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-python38-babel-0:2.7.0-12.el7
Fixed · RHSA-2021:3254
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-python38-python-0:3.8.11-2.el7
Fixed · RHSA-2021:3254
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-python38-python-cryptography-0:2.8-5.el7
Fixed · RHSA-2021:3254
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-python38-python-jinja2-0:2.10.3-6.el7
Fixed · RHSA-2021:3254
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-python38-python-lxml-0:4.4.1-7.el7
Fixed · RHSA-2021:3254
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-python38-python-pip-0:19.3.1-2.el7
Fixed · RHSA-2021:3254
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-python38-python-urllib3-0:1.25.7-7.el7
Fixed · RHSA-2021:3254
Red Hat Enterprise Linux 6
python
Out of support scope
Red Hat Enterprise Linux 7
python
Out of support scope
Red Hat Enterprise Linux 7
python3
Out of support scope
Red Hat Enterprise Linux 8
python36:3.6/python36
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | python27:2.7-8060020220210185952.8cdc2268 | Fixed | RHSA-2022:1821 |
| Red Hat Enterprise Linux 8 | python3-0:3.6.8-39.el8_4 | Fixed | RHSA-2021:4057 |
| Red Hat Enterprise Linux 8 | python3-0:3.6.8-39.el8_4 | Fixed | RHSA-2021:4057 |
| Red Hat Enterprise Linux 8 | python38-devel:3.8-8060020220120164031.5294be16 | Fixed | RHSA-2022:1764 |
| Red Hat Enterprise Linux 8 | python38:3.8-8060020220120164031.5294be16 | Fixed | RHSA-2022:1764 |
| Red Hat Enterprise Linux 8 | python39-devel:3.9-8050020210811100211.d428a79b | Fixed | RHSA-2021:4160 |
| Red Hat Enterprise Linux 8 | python39:3.9-8050020210811100211.d428a79b | Fixed | RHSA-2021:4160 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | python27-python-0:2.7.18-4.el7 | Fixed | RHSA-2022:1663 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-python38-babel-0:2.7.0-12.el7 | Fixed | RHSA-2021:3254 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-python38-python-0:3.8.11-2.el7 | Fixed | RHSA-2021:3254 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-python38-python-cryptography-0:2.8-5.el7 | Fixed | RHSA-2021:3254 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-python38-python-jinja2-0:2.10.3-6.el7 | Fixed | RHSA-2021:3254 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-python38-python-lxml-0:4.4.1-7.el7 | Fixed | RHSA-2021:3254 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-python38-python-pip-0:19.3.1-2.el7 | Fixed | RHSA-2021:3254 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-python38-python-urllib3-0:1.25.7-7.el7 | Fixed | RHSA-2021:3254 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-python38-babel-0:2.7.0-12.el7 | Fixed | RHSA-2021:3254 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-python38-python-0:3.8.11-2.el7 | Fixed | RHSA-2021:3254 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-python38-python-cryptography-0:2.8-5.el7 | Fixed | RHSA-2021:3254 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-python38-python-jinja2-0:2.10.3-6.el7 | Fixed | RHSA-2021:3254 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-python38-python-lxml-0:4.4.1-7.el7 | Fixed | RHSA-2021:3254 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-python38-python-pip-0:19.3.1-2.el7 | Fixed | RHSA-2021:3254 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-python38-python-urllib3-0:1.25.7-7.el7 | Fixed | RHSA-2021:3254 |
| Red Hat Enterprise Linux 6 | python | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | python | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | python3 | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | python36:3.6/python36 | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Applications that use AbstractBasicAuthHandler, HTTPBasicAuthHandler and ProxyBasicAuthHandler may be affected by this flaw. Other classes may use the vulnerable method http_error_auth_reqed in AbstractBasicAuthHandler as well. This flaw is out of support scope for versions of Python shipped in Red Hat Enterprise Linux 7 base OS and Red Hat Enterprise Linux 6. For more information about support life cycles, please see https://access.redhat.com/support/policy/updates/errata/
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:S/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (20 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.67% (0.04675) | 91.48th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.67% (0.04675) | 90.57th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.70% (0.00702) | 71.28th | v4 (v2025.03.14) |
| Nov 18, 2025 | 8.85% (0.08854) | 91.69th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.39% (0.00387) | 57.76th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.34% (0.00342) | 72.38th | v3 (v2023.03.01) |
| May 29, 2024 | 0.34% (0.00342) | 71.48th | v3 (v2023.03.01) |
| May 3, 2024 | 0.27% (0.00265) | 65.95th | v3 (v2023.03.01) |
| Oct 27, 2023 | 0.27% (0.00265) | 63.86th | v3 (v2023.03.01) |
| Sep 28, 2023 | 0.22% (0.00216) | 59.12th | v3 (v2023.03.01) |
| Jul 9, 2023 | 0.21% (0.00205) | 57.37th | v3 (v2023.03.01) |
| Jul 1, 2023 | 0.14% (0.00144) | 49.28th | v3 (v2023.03.01) |
| Jun 12, 2023 | 0.14% (0.00136) | 47.82th | v3 (v2023.03.01) |
| Mar 14, 2023 | 0.13% (0.00125) | 45.30th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.09% (0.00086) | 34.79th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.03% (0.01034) | 41.69th | v2 (v2022.01.01) |
| Sep 17, 2022 | 1.03% (0.01034) | 40.00th | v2 (v2022.01.01) |
| Apr 9, 2022 | 1.03% (0.01034) | 37.99th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.95% (0.00950) | 28.61th | v2 (v2022.01.01) |
| Mar 8, 2022 | 0.95% (0.00950) | 14.31th | v2 (v2022.01.01) |
References (16)
- https://access.redhat.com/security/cve/CVE-2021-3733 Vendor Advisory
- https://bugs.python.org/issue43075 ExploitIssue TrackingPatchVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1995234 Issue TrackingThird Party Advisory
- https://docs.python.org/3.6/whatsnew/changelog.html#python-3-6-14-final
- https://docs.python.org/3.7/whatsnew/changelog.html#python-3-7-11-final
- https://docs.python.org/3.8/whatsnew/changelog.html#python-3-8-10-final
- https://docs.python.org/3.9/whatsnew/changelog.html#python-3-9-5-final
- https://github.com/python/cpython/commit/7215d1ae25525c92b026166f9d5cac85fb PatchThird Party Advisory
- https://github.com/python/cpython/pull/24391 PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html mailing-list
- https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html mailing-list
- https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html
- https://nvd.nist.gov/vuln/detail/CVE-2021-3733
- https://security.netapp.com/advisory/ntap-20220407-0001/ Third Party Advisory
- https://ubuntu.com/security/CVE-2021-3733 PatchThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2021-3733
Change history (0)
No recorded changes yet.