CVE-2021-32837

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/01/2023
Last modified:
22/12/2025

Description

mechanize, a library for automatically interacting with HTTP web servers, contains a regular expression that is vulnerable to regular expression denial of service (ReDoS) prior to version 0.4.6. If a web server responds in a malicious way, then mechanize could crash. Version 0.4.6 has a patch for the issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mechanize_project:mechanize:*:*:*:*:*:python:*:* 0.4.6 (excluding)