Lucene search

K
osvGoogleOSV:PSF-2021-2
HistoryMay 06, 2021 - 12:00 a.m.

ipaddress leading zeros in IPv4 address

2021-05-0600:00:00
Google
osv.dev
20
python
ipaddress library
vulnerability
leading zero
octets
ip addresses
access control

AI Score

9.3

Confidence

High

EPSS

0.008

Percentile

81.7%

In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.