PT-2021-8204 · Pypi+4 · Mpmath+4

Os-Ws

·

Published

2021-06-21

·

Updated

2025-07-03

·

CVE-2021-29063

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Mpmath versions 1.0.0 through 1.2.1
Description A Regular Expression Denial of Service (ReDOS) issue is present in the mpmathify function of the Mpmath library for Python. This issue can be exploited by a remote attacker to cause a denial of service. The mpmathify function is the vulnerable component. No information is provided about the estimated number of potentially affected devices or real-world incidents.
Recommendations For Mpmath versions 1.0.0 through 1.2.1, consider disabling the mpmathify function as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2024-11296
CVE-2021-29063
GHSA-F865-M6CQ-J9VX
MGASA-2021-0479
OPENSUSE-SU-2024:13280-1
PYSEC-2021-427
USN-7160-1

Affected Products

Debian
Linuxmint
Mpmath
Red Os
Ubuntu