Description
In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3980-1 | python3.9 security update |
EUVD |
EUVD-2021-16395 | In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses. |
Ubuntu USN |
USN-4973-1 | Python vulnerability |
Ubuntu USN |
USN-4973-2 | Python vulnerability |
Ubuntu USN |
USN-6891-1 | Python vulnerabilities |
References
History
Mon, 03 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Subscriptions
Oracle
Subscribe
Communications Cloud Native Core Automated Test Suite
Subscribe
Communications Cloud Native Core Binding Support Function
Subscribe
Communications Cloud Native Core Network Slice Selection Function
Subscribe
Graalvm
Subscribe
Zfs Storage Appliance Kit
Subscribe
Python
Subscribe
Python
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Rhel Software Collections
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-03T21:44:43.122Z
Reserved: 2021-04-01T00:00:00.000Z
Link: CVE-2021-29921
No data.
Status : Modified
Published: 2021-05-06T13:15:12.573
Modified: 2025-11-03T22:15:48.057
Link: CVE-2021-29921
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN