← All CVEs

CVE-2021-3737

high · 7.5

A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.

7.5
CVSS
11.6%
EPSS (exploit prob.)
96th
EPSS percentile
2022-03-04
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-835CWE-400

Affected products

VendorProductAffected versions
pythonpython>= 3.6.0, < 3.6.14
pythonpython>= 3.7.0, < 3.7.11
pythonpython>= 3.8.0, < 3.8.11
pythonpython>= 3.9.0, < 3.9.6
redhatcodeready_linux_builder8.0
redhatcodeready_linux_builder_for_ibm_z_systems8.0
redhatcodeready_linux_builder_for_power_little_endian8.0
redhatenterprise_linux6.0
redhatenterprise_linux7.0
redhatenterprise_linux8.0
redhatenterprise_linux_for_ibm_z_systems8.0
redhatenterprise_linux_for_power_little_endian8.0
fedoraprojectfedora33
fedoraprojectfedora34
canonicalubuntu_linux14.04
canonicalubuntu_linux16.04
canonicalubuntu_linux18.04
canonicalubuntu_linux20.04
canonicalubuntu_linux21.04
netapphciall versions
netappmanagement_services_for_element_softwareall versions
netappnetapp_xcp_smball versions
netappontap_select_deploy_administration_utilityall versions
netappxcp_nfsall versions
oraclecommunications_cloud_native_core_binding_support_function22.1.3
oraclecommunications_cloud_native_core_network_exposure_function22.1.1
oraclecommunications_cloud_native_core_policy22.2.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-3737