PT-2021-7372 · Python+10 · Python+10

Published

2021-05-03

·

Updated

2026-02-22

·

CVE-2021-3737

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Python (affected versions not specified)
Description A flaw in the HTTP client code of Python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability. This issue is related to the urllib component and can lead to uncontrolled resource consumption.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Infinite Loop

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4160
ALSA-2022:1764
ALSA-2022:1821
ALSA-2022:1986
ALT-PU-2021-2084
ALT-PU-2021-2653
ALT-PU-2021-3010
ALT-PU-2022-3044
ALT-PU-2024-3474
BDU:2022-05830
BIT-LIBPYTHON-2021-3737
BIT-PYTHON-2021-3737
BIT-PYTHON-MIN-2021-3737
CESA-2021_4160
CESA-2022_1764
CESA-2022_1821
CESA-2022_1986
CVE-2021-3737
DLA-2808-1
DLA-3432-1
DLA-3477-1
DLA-3966-1
DLA-3980-1
MGASA-2021-0435
OESA-2021-1401
OPENSUSE-SU-2021:1418-1
OPENSUSE-SU-2021:3489-1
OPENSUSE-SU-2021:4104-1
OPENSUSE-SU-2021_1418-1
OPENSUSE-SU-2021_3489-1
OPENSUSE-SU-2021_4104-1
OPENSUSE-SU-2022_1485-1
OPENSUSE-SU-2024:11202-1
OPENSUSE-SU-2024:11284-1
OPENSUSE-SU-2024:11286-1
PSF-2022-7
RHSA-2021:4160
RHSA-2021_4160
RHSA-2022:1663
RHSA-2022:1764
RHSA-2022:1821
RHSA-2022:1986
RHSA-2022_1764
RHSA-2022_1821
RHSA-2022_1986
RLSA-2021:4160
RLSA-2022:1764
RLSA-2022:1821
SUSE-SU-2021:3477-1
SUSE-SU-2021:3486-1
SUSE-SU-2021:3489-1
SUSE-SU-2021:3524-1
SUSE-SU-2021:4015-1
SUSE-SU-2021:4015-2
SUSE-SU-2021:4104-1
SUSE-SU-2022:1485-1
USN-5083-1
USN-5199-1
USN-5200-1
USN-5201-1
USN-6891-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Python
Red Hat
Rocky Linux
Suse
Ubuntu