{"schema_version":"1.7.5","id":"CVE-2021-33516","published":"2021-05-24T15:15:07.400Z","modified":"2026-07-08T22:14:02.868410Z","related":["ALSA-2021:2363","SUSE-SU-2021:2080-1","SUSE-SU-2021:2153-1","openSUSE-SU-2021:0917-1","openSUSE-SU-2021:2153-1","openSUSE-SU-2024:10837-1"],"details":"An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web server can exploit this vulnerability to trick a victim's browser into triggering actions against local UPnP services implemented using this library. Depending on the affected service, this could be used for data exfiltration, data tempering, etc.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gnome/gupnp","events":[{"introduced":"0"},{"fixed":"ab250af4c92c0b495af360f8a903719c49446cde"},{"introduced":"d1e3078932f19b4d2c199c8522abaf90b77caf93"},{"fixed":"0aa35cd9c750e97327a850df653dfae723905865"}],"database_specific":{"cpe":"cpe:2.3:a:gnome:gupnp:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.0.7"},{"introduced":"1.1.0"},{"fixed":"1.2.5"}],"source":"CPE_RANGE"}}],"versions":["gupnp-1.0.6","gupnp-1.2.4","gupnp-1.0.5","gupnp-1.2.3","gupnp-1.2.2","gupnp-1.0.4","gupnp-1.2.1","gupnp-1.2.0","gupnp-1.1.2","gupnp-1.1.1","gupnp-1.1.0","gupnp-1.0.3","gupnp-1.0.2","gupnp-1.0.1","gupnp-1.0.0","gupnp-0.99.0","gupnp-0.20.18","gupnp-0.20.17","gupnp-0.20.16","gupnp-0.20.15","gupnp-0.20.14","gupnp-0.20.13","gupnp-0.20.12","gupnp-0.20.11","0.20.11","gupnp-0.20.10","gupnp-0.20.9","gupnp-0.20.8","gupnp-0.20.7","gupnp-0.20.6","gupnp-0.20.5","gupnp-0.20.4","gupnp-0.20.3","gupnp-0.20.2","gupnp-0.20.1","gupnp-0.20.0","gupnp-0.19.4","gupnp-0.19.3","gupnp-0.19.2","gupnp-0.19.1","gupnp-0.19.0","gupnp-0.18.0","gupnp-0.17.2","gupnp-0.17.1","gupnp-0.17.0","gupnp-0.16.1","gupnp-0.16.0","gupnp-0.15.1","gupnp-0.15.0","gupnp-0.14.0","gupnp-0.13.5","gupnp-0.13.4","gupnp-0.13.3","gupnp-0.13.2","gupnp-0.13.1","gupnp-0.13","gupnp-0.12.8","gupnp-0.12.7","gupnp-0.12.6","gupnp-0.12.5","gupnp-0.12.4","gupnp-0.12.3","gupnp-0.12.2","gupnp-0.12.1","gupnp-0.12","gupnp-0.10"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-33516.json"}}],"references":[{"type":"REPORT","url":"https://gitlab.gnome.org/GNOME/gupnp/-/issues/24"},{"type":"FIX","url":"https://discourse.gnome.org/t/security-relevant-releases-for-gupnp-issue-cve-2021-33516/6536"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N"}]}