peter bassill · operator
$ cve CVE-2021-29921 JSON

CVE-2021-29921

9.8
CRITICAL · CVSS 3.1 · EPSS 6.9% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.88% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploitnone known
Published2021-05-06
Last modified2026-06-17

Affected (6)

VendorProduct
oraclecommunications cloud native core automated test suite
oraclecommunications cloud native core binding support function
oraclecommunications cloud native core network slice selection function
oraclegraalvm
oraclezfs storage appliance kit
pythonpython

References

→ the Explorer  ·  watch your stack  ·  NVD