{"schema_version":"1.8.0","id":"CVE-2021-29921","published":"2021-05-06T13:15:12.573Z","modified":"2026-08-07T11:48:36.988395612Z","aliases":["BIT-libpython-2021-29921","BIT-python-2021-29921","BIT-python-min-2021-29921","PSF-2021-2"],"related":["ALSA-2021:4160","ALSA-2021:4162","SUSE-FU-2022:0444-1","SUSE-FU-2022:0445-1","SUSE-SU-2021:2940-1","openSUSE-SU-2024:11286-1"],"details":"In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/graalvm/graalvm-ce-builds","events":[{"introduced":"cf616f9f924f9e60b6158ff4aaed8306382b4c31"},{"last_affected":"a748f59635430848730ca95f41a9f7fa1f26b12b"}],"database_specific":{"cpe":["cpe:2.3:a:oracle:graalvm:20.3.2:*:*:*:enterprise:*:*:*","cpe:2.3:a:oracle:graalvm:21.1.0:*:*:*:enterprise:*:*:*"],"extracted_events":[{"introduced":"20.3.2"},{"last_affected":"20.3.2"},{"introduced":"21.1.0"},{"last_affected":"21.1.0"}],"source":"CPE_STRING"}}],"versions":["20.3.2","21.1.0","vm-21.1.0","vm-20.3.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-29921.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/python/cpython","events":[{"introduced":"fa919fdf2583bdfead1df00e842f24f30b2a34bf"},{"fixed":"07119dd38c9a6e5da84ca8a0a46acdf8a3e60ecf"},{"introduced":"9cf6752276e6fcfd0c23fdb064ad27f448aaaf75"},{"fixed":"0a7dcbdb13f1f2ab6e76e1cff47e80fb263f5da0"}],"database_specific":{"cpe":"cpe:2.3:a:python:python:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.8.0"},{"fixed":"3.8.12"},{"introduced":"3.9.0"},{"fixed":"3.9.5"}],"source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-29921.json"}}],"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujul2022.html"},{"type":"ADVISORY","url":"https://docs.python.org/3/library/ipaddress.html"},{"type":"ADVISORY","url":"https://github.com/python/cpython/blob/63298930fb531ba2bb4f23bc3b915dbf1e17e9e1/Misc/NEWS.d/3.8.0a4.rst"},{"type":"ADVISORY","url":"https://github.com/sickcodes"},{"type":"ADVISORY","url":"https://python-security.readthedocs.io/vuln/ipaddress-ipv4-leading-zeros.html"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202305-02"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20210622-0003/"},{"type":"FIX","url":"https://bugs.python.org/issue36384"},{"type":"FIX","url":"https://github.com/python/cpython/pull/12577"},{"type":"FIX","url":"https://github.com/python/cpython/pull/25099"},{"type":"FIX","url":"https://www.oracle.com//security-alerts/cpujul2021.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuapr2022.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujan2022.html"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuoct2021.html"},{"type":"EVIDENCE","url":"https://github.com/sickcodes/security/blob/master/advisories/SICK-2021-014.md"},{"type":"EVIDENCE","url":"https://sick.codes/sick-2021-014"}],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.8.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.8.0"},{"last_affected":"1.8.0"}],"source":"CPE_STRING","vendor_product":"oracle:communications_cloud_native_core_automated_test_suite"},{"cpes":["cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:1.11.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.11.0"},{"last_affected":"1.11.0"}],"source":"CPE_STRING","vendor_product":"oracle:communications_cloud_native_core_binding_support_function"},{"cpes":["cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:1.8.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.8.0"},{"last_affected":"1.8.0"}],"source":"CPE_STRING","vendor_product":"oracle:communications_cloud_native_core_network_slice_selection_function"},{"cpes":["cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8.8"},{"last_affected":"8.8"}],"source":"CPE_STRING","vendor_product":"oracle:zfs_storage_appliance_kit"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}