{"id":"CVE-2021-29063","details":"A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Mpmath v1.0.0 through v1.2.1 when the mpmathify function is called.","aliases":["GHSA-f865-m6cq-j9vx","PYSEC-2021-427"],"modified":"2026-07-08T06:00:10.199974836Z","published":"2021-06-21T20:15:09.477Z","related":["CGA-wfhm-8wcx-ghc4","openSUSE-SU-2024:13280-1"],"database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"33"},{"last_affected":"33"},{"introduced":"34"},{"last_affected":"34"},{"introduced":"35"},{"last_affected":"35"}],"source":"CPE_STRING","vendor_product":"fedoraproject:fedora","cpes":["cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*"]}]},"references":[{"type":"WEB","url":"https://github.com/mpmath/mpmath/releases/tag/1.3.0"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3M5O55E7VUDMXCPQR6MQTOIFDKHP36AA/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EIUX3XWY2K3MSO7QXMZXQQYAURARSPC5/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MS2U6GLXQSRZJE2HVUAUMVFR2DWQLCZG/"},{"type":"WEB","url":"https://www.npmjs.com/package/hosted-git-info"},{"type":"ADVISORY","url":"https://github.com/yetingli/SaveResults/blob/main/js/hosted-git-info.js"},{"type":"FIX","url":"https://github.com/fredrik-johansson/mpmath/commit/46d44c3c8f3244017fe1eb102d564eb4ab8ef750"},{"type":"FIX","url":"https://github.com/npm/hosted-git-info/pull/76"},{"type":"FIX","url":"https://github.com/yetingli/PoCs/blob/main/CVE-2021-29063/Mpmath.md"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mpmath/mpmath","events":[{"introduced":"8e21a638727567914536f4a4a63aa5fa204c40f0"},{"last_affected":"c6a35f9ee7c294bcf4e0517bc76b268843db9499"},{"fixed":"46d44c3c8f3244017fe1eb102d564eb4ab8ef750"},{"fixed":"b5c04506ef0cd4a1f1213f8389ee21c9c3551582"}],"database_specific":{"cpe":"cpe:2.3:a:mpmath:mpmath:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.0.0"},{"last_affected":"1.2.1"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["1.2.1","1.2.0-rebuild","1.2.0","1.1.0","1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-29063.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}