CVE-2021-32838: Regular Expression Denial of Service in flask-restx
Flask RESTX contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service) in emailregex.
Other sources
Flask-RESTX (pypi package flask-restx) is a community driven fork of Flask-RESTPlus. Flask-RESTX before version 0.5.1 is vulnerable to ReDoS (Regular Expression Denial of Service) in emailregex. This is fixed in version 0.5.1.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-32838?
The severity of CVE-2021-32838 is classified as high due to the potential for Denial of Service attacks.
How do I fix CVE-2021-32838?
To fix CVE-2021-32838, upgrade to Flask-RESTX version 0.5.1 or later.
What is affected by CVE-2021-32838?
CVE-2021-32838 affects the Flask-RESTX package versions prior to 0.5.1 and certain Fedora versions.
What type of vulnerability is CVE-2021-32838?
CVE-2021-32838 is classified as a Regular Expression Denial of Service (ReDoS) vulnerability.
What is the impact of CVE-2021-32838?
The impact of CVE-2021-32838 may result in application unavailability due to resource exhaustion.