Junglewise Threat Intelligence

CVE-2021-33503: urllib3 ReDoS in URL authority parser

CVE-2021-33503 · Severity: high · CVSS 7.5 · Published 2021-06-01

Technologies: Urllib3. Vendors: PyPI.

Executive brief

urllib3 is a widely used Python library for making web requests. A flaw in how it processes web addresses (URLs) allows an attacker to crash or significantly slow down an application by providing a specially crafted URL. This can lead to a denial-of-service, making the affected application or service unavailable to legitimate users.

Technical details

A Regular Expression Denial of Service (ReDoS) vulnerability exists in urllib3 due to catastrophic backtracking in the URL authority parser. When the library processes a URL containing a large number of '@' characters in the authority component, the regular expression engine requires exponential time to evaluate the input. This can be triggered remotely if an application passes attacker-controlled URLs to urllib3 or follows a malicious HTTP redirect. The issue is fixed in version 1.26.5 by optimizing the regular expression used for parsing.

Affected products

  • urllib3 urllib3 >= 1.25.4, < 1.26.5

Timeline

  • 2021-05-26: disclosed
  • 2021-05-28: patched: Fix merged in version 1.26.5
  • 2021-06-01: advisory

References

Related threats