suse · CVE-2021-33503

Quick triage

Priority: high Published: 2021-06-09 13:58:28 UTC Updated: 2026-03-05 05:18:08 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2021-33503 severity important: SUSE including 264 source package names (0.7.1-rev1.0.0-build2.2.1:python3-urllib3-1.25.10-4.3.1, 1.8.6.0.3.2.5:python3-urllib3-1.25.10-4.3.1, …), 622 product×package rows across 355 product lines (Container bci/kiwi, Container ses/7.1/cephcsi/cephcsi, … (355 product lines)): Fixed 439, Known Affected 169, Known Not Affected 14.

Description:

An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.

cvelogic Threat Intelligence