CVE-2021-3733: Fedoraproject Extra Packages For Enterprise Linux

Medium severity, CVSS 6.5. EPSS: 4.7% chance of exploitation in the next 30 days.

There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.

Affected products

  • Fedoraproject Extra Packages For Enterprise Linux: version 7.0 only
  • Fedoraproject Fedora: version 33 only; version 34 only; version 35 only; version 36 only
  • Netapp Hci Compute Node Firmware: affected versions not specified
  • Netapp Management Services For Element Software And Netapp Hci: affected versions not specified
  • Netapp Ontap Select Deploy Administration Utility: affected versions not specified
  • Netapp Solidfire, Enterprise Sds & Hci Storage Node: affected versions not specified
  • Python Python: before 3.6.14 (fixed in 3.6.14); from 3.7.0, before 3.7.11 (fixed in 3.7.11); from 3.8.0, before 3.8.10 (fixed in 3.8.10); from 3.9.0, before 3.9.5 (fixed in 3.9.5); version 3.10.0 only
  • Red Hat Codeready Linux Builder: version 8.0 only
  • Red Hat Codeready Linux Builder For IBM Z Systems: version 8.0 only
  • Red Hat Codeready Linux Builder For Power Little Endian: version 8.0 only
  • Red Hat Enterprise Linux: version 8.0 only
  • Red Hat Enterprise Linux Eus: version 8.4 only
  • Red Hat Enterprise Linux For IBM Z Systems: version 8.0 only
  • Red Hat Enterprise Linux For IBM Z Systems Eus: version 8.4 only
  • Red Hat Enterprise Linux For Power Little Endian: version 8.0 only
  • Red Hat Enterprise Linux For Power Little Endian Eus: version 8.4 only
  • Red Hat Enterprise Linux Server Aus: version 8.4 only
  • Red Hat Enterprise Linux Server For Power Little Endian Update Services For SAP Solutions: version 8.4 only
  • Red Hat Enterprise Linux Server Tus: version 8.4 only
  • Red Hat Enterprise Linux Server Update Services For SAP Solutions: version 8.4 only

Published 2022-03-10. Last modified 2026-10-08.