Description
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser) connects to, could trigger a Regular Expression Denial of Service (ReDOS) during an authentication request with a specially crafted payload that is sent by the server to the client. The greatest threat that this flaw poses is to application availability.
Remediation
References
Related Vulnerabilities
WordPress Plugin Subscriptions & Memberships for PayPal Unspecified Vulnerability (1.1.5)
Grafana Improper Input Validation Vulnerability (CVE-2022-39306)
WordPress Plugin WP to Twitter Cross-Site Request Forgery (3.2.9)
OpenSSL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-3732)