High severity8.1NVD Advisory· Published May 24, 2021· Updated Jun 17, 2026
CVE-2021-33516
CVE-2021-33516
Description
An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web server can exploit this vulnerability to trick a victim's browser into triggering actions against local UPnP services implemented using this library. Depending on the affected service, this could be used for data exfiltration, data tempering, etc.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
15- GUPnP/GUPnPdescription
- Range: <1.0.7, <1.2.5
- osv-coords13 versionspkg:rpm/almalinux/gupnppkg:rpm/almalinux/gupnp-develpkg:rpm/opensuse/gupnp&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/gupnp&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/gupnp&distro=openSUSE%20Tumbleweedpkg:rpm/suse/gupnp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP2pkg:rpm/suse/gupnp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP3pkg:rpm/suse/gupnp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP2pkg:rpm/suse/gupnp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP3pkg:rpm/suse/gupnp&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/gupnp&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP5pkg:rpm/suse/gupnp&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP2pkg:rpm/suse/gupnp&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP3
< 1.0.6-2.el8_4+ 12 more
- (no CPE)range: < 1.0.6-2.el8_4
- (no CPE)range: < 1.0.6-2.el8_4
- (no CPE)range: < 1.2.2-lp152.2.3.1
- (no CPE)range: < 1.2.2-3.3.1
- (no CPE)range: < 1.2.7-2.2
- (no CPE)range: < 1.2.2-3.3.1
- (no CPE)range: < 1.2.2-3.3.1
- (no CPE)range: < 1.2.2-3.3.1
- (no CPE)range: < 1.2.2-3.3.1
- (no CPE)range: < 0.20.18-8.3.1
- (no CPE)range: < 0.20.18-8.3.1
- (no CPE)range: < 1.2.2-3.3.1
- (no CPE)range: < 1.2.2-3.3.1
Patches
Vulnerability mechanics
References
2- discourse.gnome.org/t/security-relevant-releases-for-gupnp-issue-cve-2021-33516/6536nvdPatchVendor Advisory
- gitlab.gnome.org/GNOME/gupnp/-/issues/24nvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.