id: PYSEC-2021-108 details: An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect. affected: - package: name: urllib3 ecosystem: PyPI purl: pkg:pypi/urllib3 ranges: - type: GIT repo: https://github.com/urllib3/urllib3 events: - introduced: "0" - fixed: 2d4a3fee6de2fa45eb82169361918f759269b4ec - type: ECOSYSTEM events: - introduced: 1.25.4 - fixed: 1.26.5 versions: - 1.25.4 - 1.25.5 - 1.25.6 - 1.25.7 - 1.25.8 - 1.25.9 - 1.25.10 - 1.25.11 - 1.26.0 - 1.26.1 - 1.26.2 - 1.26.3 - 1.26.4 references: - type: ADVISORY url: https://github.com/advisories/GHSA-q2q7-5pp4-w6pg - type: FIX url: https://github.com/urllib3/urllib3/commit/2d4a3fee6de2fa45eb82169361918f759269b4ec aliases: - CVE-2021-33503 - GHSA-q2q7-5pp4-w6pg modified: "2021-07-02T18:56:20.858344Z" published: "2021-06-29T11:15:00Z"