CVE-2021-21240Disclosure(httplib2_project / httplib2)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

httplib2 is a comprehensive HTTP client library for Python. In httplib2 before version 0.19.0, a malicious server which responds with long series of "\xa0" characters in the "www-authenticate" header may cause Denial of Service (CPU burn while parsing header) of the httplib2 client accessing said server. This is fixed in version 0.19.0 which contains a new implementation of auth headers parsing using the pyparsing library.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • httplib2

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Products
httplib2

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-21: 203-21
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Security Bug Aggregator@BugsAggregator
    Disclosure

    [467583833] Vulnerability: CVE-2021-21240 affecting GitOnBorg::chrome-internal::chrome::tools::cr2goog http://crbug.com/467583833

    Post summary

    The text reports CVE‑2021‑21240 affecting a Chrome internal component and links to a Chromium bug tracker entry.

    00032622
    3.1K followersView on X
  • Security Bug Aggregator@BugsAggregator
    General

    [462293362] Vulnerability: CVE-2021-21240 affecting GitOnBorg::chromium::infra::luci::luci-py http://crbug.com/462293362

    Post summary

    The post merely notes that CVE‑2021‑21240 affects a specific component and cites a Chromium bug link, without any deeper exploit or remediation details.

    00010354
    3.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphttplib2_projecthttplib2-python-

Explore more