← Back to CVE List

CVE-2021-21240

Published: 2021-02-08T20:15Z
Last Modified: 2024-11-21T05:47Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
httplib2 is a comprehensive HTTP client library for Python. In httplib2 before version 0.19.0, a malicious server which responds with long series of "\xa0" characters in the "www-authenticate" header may cause Denial of Service (CPU burn while parsing header) of the httplib2 client accessing said server. This is fixed in version 0.19.0 which contains a new implementation of auth headers parsing using the pyparsing library. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt