CVE-2021-3733EPSS p91.5%
CVE-2021-3733CVE-2021-3733
python / python
Description
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.
Scoring
| CVSS | 6.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
| EPSS | 4.67% probability of exploitation · percentile 91.5% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-08 |