CVE-2021-28861 - CVE House
Back to Database
Status published Unknown CVE-2021-28861

Python 3.x through 3.10 has an open redirection vulnerability in...

Vulnerability Description

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-28861

Credits & Attribution

No credits recorded in the NVD database.

References

Affected Vendor

Affected Software

python, fedora
Vulnerable Versions:
3.0.0, 3.8.0, 3.9.0, 3.10.0, 3.11.0, 35, 36, 37

Timeline

Official Publish: August 23rd, 2022
Last Modified: December 17th, 2025
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.