Executive brief
urllib3 is a widely used Python library for making web requests. A flaw in how it processes web addresses (URLs) allows an attacker to crash or significantly slow down an application by providing a specially crafted URL. This can lead to a denial-of-service, making the affected application or service unavailable to legitimate users.
Technical details
A Regular Expression Denial of Service (ReDoS) vulnerability exists in urllib3 due to catastrophic backtracking in the URL authority parser. When the library processes a URL containing a large number of '@' characters in the authority component, the regular expression engine requires exponential time to evaluate the input. This can be triggered remotely if an application passes attacker-controlled URLs to urllib3 or follows a malicious HTTP redirect. The issue is fixed in version 1.26.5 by optimizing the regular expression used for parsing.
Affected products
- urllib3 urllib3 >= 1.25.4, < 1.26.5
Timeline
- 2021-05-26: disclosed
- 2021-05-28: patched: Fix merged in version 1.26.5
- 2021-06-01: advisory
References
- https://api.github.com/users/NariyoshiChida
- https://github.com/NariyoshiChida
- https://api.github.com/users/NariyoshiChida/gists%7B/gist_id%7D
- https://api.github.com/users/NariyoshiChida/repos
- https://avatars.githubusercontent.com/u/11674670?v=4
- https://api.github.com/users/NariyoshiChida/events%7B/privacy%7D