View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2021-33503 severity important: SUSE including 264 source package names (0.7.1-rev1.0.0-build2.2.1:python3-urllib3-1.25.10-4.3.1, 1.8.6.0.3.2.5:python3-urllib3-1.25.10-4.3.1, …), 622 product×package rows across 355 product lines (Container bci/kiwi, Container ses/7.1/cephcsi/cephcsi, … (355 product lines)): Fixed 439, Known Affected 169, Known Not Affected 14.
An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.