CVE-2021-23336Disclosure(debian / cloud_backup)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with default configuration) and the server. This can result in malicious requests being cached as completely safe ones, as the proxy would usually not see the semicolon as a separator, and therefore would not include it in a cache key of an unkeyed parameter.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-444

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cloud_backup
  • communications_offline_mediation_controller
  • communications_pricing_design_center
  • debian_linux

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
cloud_backupcommunications_offline_mediation_controllercommunications_pricing_design_centerdebian_linuxdjangoenterprise_manager_ops_centerfedorainventory_collect_toolontap_select_deploy_administration_utilitypython

8 versions affected across 12 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-15: 1Technical Details · 2026-06-15: 106-15
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • DailyCVE@dailycve
    Disclosure

    🟠 #python-multipart, HTTP Parameter Pollution, #CVE-2021-23336 (Medium) -DC-Jun2026-447 https://dailycve.com/python-multipart-http-parameter-pollution-cve-2021-23336-medium-dc-jun2026-447/

    Post summary

    This post announces CVE-2021-23336, a medium‑severity HTTP Parameter Pollution issue in python‑multipart, without providing PoC, exploitation code, or mitigation details.

    0000036
    212 followersView on X
CPE platform detail14 entries

14 of 14 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux9.0--
Appdjangoprojectdjango---
OSfedoraprojectfedora32--
OSfedoraprojectfedora33--
OSfedoraprojectfedora34--
Appnetappcloud_backup---
Appnetappinventory_collect_tool---
Appnetappontap_select_deploy_administration_utility---
Appnetappsnapcenter---
Apporaclecommunications_offline_mediation_controller12.0.0.3.0--
Apporaclecommunications_pricing_design_center12.0.0.3.0--
Apporacleenterprise_manager_ops_center12.4.0.0--
OSoraclezfs_storage_appliance8.8--
Apppythonpython---

Explore more