Skip to content
appaloosa scout logo main rounded
HIGH 7.5

CVE-2021-3737

A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.

CVSS v3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS 0.1% percentile 30.3%

Affected tracked apps

Vulnerable CPE configurations

Vendor Product Platform Versions CPE 2.3 URI
python python Windows ≥3.6.0 <3.6.14 cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
python python Windows ≥3.7.0 <3.7.11 cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
python python Windows ≥3.8.0 <3.8.11 cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
python python Windows ≥3.9.0 <3.9.6 cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
View on NVD ↗