VYPR
High severity7.5NVD Advisory· Published Sep 10, 2021· Updated Jun 17, 2026

CVE-2021-40839

CVE-2021-40839

Description

The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabling a remote attack that consumes CPU and memory.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
rencodePyPI
<= 1.0.6

Affected products

5
  • cpe:2.3:a:rencode_project:rencode:*:*:*:*:*:python:*:*
    Range: <=1.0.6
  • cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
    • cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
  • rencode/rencodedescription
  • ghsa-coords
    Range: <= 1.0.6

Patches

Vulnerability mechanics

References

13

News mentions

0

No linked articles in our index yet.