High severity7.5NVD Advisory· Published Jun 21, 2021· Updated Jun 17, 2026
CVE-2021-29063
CVE-2021-29063
Description
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Mpmath v1.0.0 through v1.2.1 when the mpmathify function is called.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mpmathPyPI | < 1.3.0 | 1.3.0 |
Affected products
14cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- Mpmath/Mpmathdescription
- osv-coords9 versionspkg:apk/chainguard/py3.10-mpmathpkg:apk/chainguard/py3.11-mpmathpkg:apk/chainguard/py3.12-mpmathpkg:apk/chainguard/py3.13-mpmathpkg:apk/wolfi/py3.10-mpmathpkg:apk/wolfi/py3.11-mpmathpkg:apk/wolfi/py3.12-mpmathpkg:apk/wolfi/py3.13-mpmathpkg:pypi/mpmath
< 1.4.0-r1+ 8 more
- (no CPE)range: < 1.4.0-r1
- (no CPE)range: < 1.4.0-r1
- (no CPE)range: < 1.4.0-r1
- (no CPE)range: < 1.4.0-r1
- (no CPE)range: < 1.4.0-r1
- (no CPE)range: < 1.4.0-r1
- (no CPE)range: < 1.4.0-r1
- (no CPE)range: < 1.4.0-r1
- (no CPE)range: < 1.3.0
Patches
Vulnerability mechanics
References
19- github.com/fredrik-johansson/mpmath/commit/46d44c3c8f3244017fe1eb102d564eb4ab8ef750nvdPatchThird Party AdvisoryWEB
- github.com/npm/hosted-git-info/pull/76nvdPatchThird Party AdvisoryWEB
- github.com/yetingli/PoCs/blob/main/CVE-2021-29063/Mpmath.mdnvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-f865-m6cq-j9vxghsaADVISORY
- github.com/yetingli/SaveResults/blob/main/js/hosted-git-info.jsnvdNot ApplicableThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-29063ghsaADVISORY
- github.com/fredrik-johansson/mpmath/commit/c811b37c65a4372a7ce613111d2a508c204f9833ghsaWEB
- github.com/fredrik-johansson/mpmath/issues/548ghsaWEB
- github.com/mpmath/mpmath/commit/c811b37c65a4372a7ce613111d2a508c204f9833ghsaWEB
- github.com/mpmath/mpmath/pull/570ghsaWEB
- github.com/mpmath/mpmath/releases/tag/1.3.0nvdWEB
- github.com/pypa/advisory-database/tree/main/vulns/mpmath/PYSEC-2021-427.yamlghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/3M5O55E7VUDMXCPQR6MQTOIFDKHP36AAghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/EIUX3XWY2K3MSO7QXMZXQQYAURARSPC5ghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/MS2U6GLXQSRZJE2HVUAUMVFR2DWQLCZGghsaWEB
- www.npmjs.com/package/hosted-git-infonvdProductWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3M5O55E7VUDMXCPQR6MQTOIFDKHP36AA/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EIUX3XWY2K3MSO7QXMZXQQYAURARSPC5/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MS2U6GLXQSRZJE2HVUAUMVFR2DWQLCZG/nvd
News mentions
0No linked articles in our index yet.