yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2021-29063
Component Overview
Vulnerability Overview
Name
CVE-2021-29063
Source
NVD (
link
)
Debian (
link
)
Description
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Mpmath v1.0.0 through v1.2.1 when the mpmathify function is called.
CWEs
CWE-770
Published Date
Jun 21, 2021
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/fredrik-johansson/mpmath/commit/46d44c3c8f3244017fe1eb102d564eb4ab8ef750
Patch
https://github.com/npm/hosted-git-info/pull/76
Patch
https://github.com/yetingli/PoCs/blob/main/CVE-2021-29063/Mpmath.md
Exploit
https://github.com/yetingli/SaveResults/blob/main/js/hosted-git-info.js
Not Applicable
https://www.npmjs.com/package/hosted-git-info
Product
https://github.com/fredrik-johansson/mpmath/commit/46d44c3c8f3244017fe1eb102d564eb4ab8ef750
Patch
https://github.com/npm/hosted-git-info/pull/76
Patch
https://github.com/yetingli/PoCs/blob/main/CVE-2021-29063/Mpmath.md
Exploit
https://github.com/yetingli/SaveResults/blob/main/js/hosted-git-info.js
Not Applicable
https://www.npmjs.com/package/hosted-git-info
Product
Analysis
#
Affected Component
Analysis
python3-mpmath
Patched
Vulnerability Ratings
#
7.5
CVSSv31
5
CVSSv2
Others affected component
#
Name
Project
Project Version
Version
Status
python3-mpmath
yocto
scarthgap
1.3.0
Not Affected
Resolved with patches
#
python3-mpmath (yocto:kirkstone)
#
Title
Author
Resolve
1
Fix ReDOS vulnerability
Vinzent Steinberg <Vinzent.Steinberg@gmail.com>
CVE-2021-29063