High severity7.5NVD Advisory· Published Feb 8, 2021· Updated Jun 17, 2026
CVE-2021-21240
CVE-2021-21240
Description
httplib2 is a comprehensive HTTP client library for Python. In httplib2 before version 0.19.0, a malicious server which responds with long series of "\xa0" characters in the "www-authenticate" header may cause Denial of Service (CPU burn while parsing header) of the httplib2 client accessing said server. This is fixed in version 0.19.0 which contains a new implementation of auth headers parsing using the pyparsing library.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
httplib2PyPI | < 0.19.0 | 0.19.0 |
Affected products
18- ghsa-coords17 versionspkg:pypi/httplib2pkg:rpm/opensuse/python-httplib2&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/python-httplib2&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/python-httplib2&distro=openSUSE%20Tumbleweedpkg:rpm/suse/python-httplib2&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/python-httplib2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/python-httplib2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/python-httplib2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP2pkg:rpm/suse/python-httplib2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP3pkg:rpm/suse/python-httplib2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2012pkg:rpm/suse/python-httplib2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015pkg:rpm/suse/python-httplib2&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/python-httplib2&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/python-httplib2&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/python-httplib2&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/python-httplib2&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209pkg:rpm/suse/python-httplib2&distro=SUSE%20Package%20Hub%2015%20SP2
< 0.19.0+ 16 more
- (no CPE)range: < 0.19.0
- (no CPE)range: < 0.19.0-lp152.6.3.1
- (no CPE)range: < 0.19.0-3.3.1
- (no CPE)range: < 0.19.1-1.2
- (no CPE)range: < 0.19.0-7.3.1
- (no CPE)range: < 0.19.0-3.3.1
- (no CPE)range: < 0.19.0-3.3.1
- (no CPE)range: < 0.19.0-3.3.1
- (no CPE)range: < 0.19.0-3.3.1
- (no CPE)range: < 0.19.0-7.7.1
- (no CPE)range: < 0.19.0-1.8.1
- (no CPE)range: < 0.19.0-7.7.1
- (no CPE)range: < 0.19.0-7.3.1
- (no CPE)range: < 0.19.0-8.3.4
- (no CPE)range: < 0.19.0-7.3.1
- (no CPE)range: < 0.19.0-8.3.4
- (no CPE)range: < 0.19.0-bp152.3.3.1
- Range: < 0.19.0
Patches
Vulnerability mechanics
References
7- github.com/httplib2/httplib2/commit/bd9ee252c8f099608019709e22c0d705e98d26bcnvdPatchThird Party AdvisoryWEB
- github.com/httplib2/httplib2/pull/182nvdPatchThird Party AdvisoryWEB
- github.com/httplib2/httplib2/security/advisories/GHSA-93xj-8mrv-444mnvdExploitMitigationThird Party AdvisoryWEB
- github.com/advisories/GHSA-93xj-8mrv-444mghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-21240ghsaADVISORY
- pypi.org/project/httplib2nvdProductThird Party AdvisoryWEB
- github.com/pypa/advisory-database/tree/main/vulns/httplib2/PYSEC-2021-16.yamlghsaWEB
News mentions
0No linked articles in our index yet.