Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-3737

26
FAUCET Score

CVE-2021-3737 describes a denial-of-service vulnerability in Python's HTTP client code, affecting products from vendors like Canonical, Fedora, NetApp, Oracle, and Red Hat. An attacker controlling an HTTP server can exploit this flaw to induce an infinite loop in a client script, consuming CPU resources. Rated 7.5 HIGH, this vulnerability has a low attack complexity and requires no user interaction or privileges, primarily impacting system availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.6.0, < 3.6.14CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.7.0, < 3.7.11CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.8.0, < 3.8.11CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.9.0, < 3.9.6CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:a:redhat:codeready_linux_builder:8.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
11.58%
Probability of exploitation in next 30 days
EPSS Percentile
95.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.1158 is in the 93rd percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (19)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: cm1 python3 3.7.11-1 on CBL Mariner 1.0Fixed in: 3.7.11-1
microsoftpatch availablevia msrc
Product: 18889-16820Fixed in: 3.7.11-1
nodejspatch availablevia llm_extracted
View patch
oraclepatch availablevia nvd_reference
View patch
pjsippatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python39-devel:3.9-8050020210811100211.d428a79b
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python38:3.8-8060020220120164031.5294be16
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python38-devel:3.8-8060020220120164031.5294be16
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python27:2.7-8060020220210185952.8cdc2268
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3-0:3.6.8-45.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: python27-python-0:2.7.18-4.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python39:3.9-8050020210811100211.d428a79b
View patch
redhatpatch availablevia nvd_reference
View patch
ubuntupatch availablevia nvd_reference
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: inkscape:flatpak/python2
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: gimp:flatpak/python2
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: python
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python36:3.6/python36

Vendor Advisories (4)

nodejsllm-nodejs-302528ae26f0d946CRITICAL

HP ThinPro 8.1 SP4 Security Updates

Oct 29, 2024
pjsipllm-pjsip-7ba3ec379210ac70CRITICAL

HP ThinPro 8.1 SP4 Security Updates

Oct 29, 2024
microsoft2022-Mar/CVE-2021-3737Important

A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker who controls the HTTP server to make the client script enter an infinite loop consuming CPU time. The highest threat from this vulnerability is to system availability.

Mar 8, 2022
redhatCVE-2021-3737Low

python: urllib: HTTP client possible infinite loop on a 100 Continue response

Aug 9, 2021

References

lists.debian.org / debian-lts-announce/2024/11/msg00024.html
lists.debian.org / debian-lts-announce/2024/12/msg00000.html
bugs.python.org / issue44022
ExploitIssue TrackingVendor Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingPatchThird Party Advisory
github.com / python/cpython/pull/25916
PatchThird Party Advisory
github.com / python/cpython/pull/26503
PatchThird Party Advisory
lists.debian.org / debian-lts-announce/2023/05/msg00024.html
lists.debian.org / debian-lts-announce/2023/06/msg00039.html
python-security.readthedocs.io / vuln/urllib-100-continue-loop.html
PatchThird Party Advisory
security.netapp.com / advisory/ntap-20220407-0009
Third Party Advisory
ubuntu.com / security/CVE-2021-3737
PatchThird Party Advisory
oracle.com / security-alerts/cpujul2022.html
PatchThird Party Advisory