StackRadar

CVE-2021-33503

High

Advisory

Published 1 Jun 2021In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.033
88th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
159
of 17,781 indexed, latest versions
Container images
165
deployed by those charts
Fix available
3 of 3
affected packages

Catastrophic backtracking in URL authority parser when passed URL containing many @ characters

Carried by container images the latest versions of 159 of 17,781 indexed charts deploy, on 165 images.

Affected packageAffected versionsFixed inImages
urllib3pypi1.7.1, 1.25.2, 1.25.3, 1.25.7+9 more1.26.5148
python-pipdeb20.0.2-5ubuntu1.1, 20.0.2-5ubuntu1.5, 20.0.2-5ubuntu1.620.0.2-5ubuntu1.724
python-urllib3deb1.25.8-2ubuntu0.11.25.8-2ubuntu0.215
OSV records
GHSA-q2q7-5pp4-w6pgUBUNTU-CVE-2021-33503PYSEC-2021-108
Also known as
USN-5812-1

Charts affected

159 by stars
ChartLatestAffected imagesRadar Score
horcruxstakewise1.0.11 of 1See more

horcrux stakewise 1.0.1

1 of the 1 container images this version deploys carry CVE-2021-33503.

Container imageDigestPackageFixed in
stakewiselabs/bls-horcrux:v1.0.02afd0c0b34cb
urllib3@1.26.2
1.26.5

Open the chart page →

1,421
cost-analyzerstatcan1.82.21 of 9See more

cost-analyzer statcan 1.82.2

1 of the 9 container images this version deploys carry CVE-2021-33503.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:1.12.089739be9ff38
urllib3@1.25.11
1.26.5

Open the chart page →

16,506
datapusherstatcan1.0.01 of 1See more

datapusher statcan 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-33503.

Container imageDigestPackageFixed in
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
urllib3@1.25.10
1.26.5

Open the chart page →

3,044
prometheus-operatorstatcan0.2.21 of 7See more

prometheus-operator statcan 0.2.2

1 of the 7 container images this version deploys carry CVE-2021-33503.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.1.1517b98eecdf6d1
urllib3@1.25.9
1.26.5

Open the chart page →

12,237
gtmetrix-bqt3n1.0.01 of 1See more

gtmetrix-bq t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-33503.

Container imageDigestPackageFixed in
t3nde/gtmetrix-bq:0.2.0d2939e9a719b
urllib3@1.25.9
1.26.5

Open the chart page →

1,287
jenkinstnh2.7.11 of 2See more

jenkins tnh 2.7.1

1 of the 2 container images this version deploys carry CVE-2021-33503.

Container imageDigestPackageFixed in
kiwigrid/k8s-sidecar:0.1.193170069ff0976
urllib3@1.25.10
1.26.5

Open the chart page →

4,423
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2021-33503.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
urllib3@1.26.3
1.26.5

Open the chart page →

4,086
docker-hub-rate-limit-exporterwiremindVerified publisher0.3.01 of 1See more

docker-hub-rate-limit-exporter wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2021-33503.

Container imageDigestPackageFixed in
viadee/docker-hub-rate-limit-exporter:version-1.52e27e3b3ee56
urllib3@1.26.3
1.26.5

Open the chart page →

1,843
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2021-33503.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
urllib3@1.25.11
1.26.5

Open the chart page →

2,643

Container images carrying it

165 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
urllib3@1.25.8
1.26.5
1
ghcr.io/alexanderbabel/database-s3-backup:1.3.33191b771a6f2
urllib3@1.25.11
1.26.5
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
urllib3@1.25.8
1.26.5
1
ghcr.io/grofers/legend:0.1d6e901ad0ebd
urllib3@1.25.11
1.26.5
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
python-urllib3@1.25.8-2ubuntu0.1
urllib3@1.25.8
1.25.8-2ubuntu0.2
1.26.5
1
ghcr.io/linuxserver/mylar3:version-v0.5.3b96f0e97ab3f
urllib3@1.26.2
1.26.5
1
ghcr.io/linuxserver/tvheadend:version-eb59284b66c4c9e18e40
urllib3@1.25.9
1.26.5
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
python-pip@20.0.2-5ubuntu1.6
20.0.2-5ubuntu1.7
1
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
urllib3@1.26.2
1.26.5
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
python-pip@20.0.2-5ubuntu1.6
20.0.2-5ubuntu1.7
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
python-pip@20.0.2-5ubuntu1.6
20.0.2-5ubuntu1.7
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
python-urllib3@1.25.8-2ubuntu0.1
urllib3@1.25.8
1.25.8-2ubuntu0.2
1.26.5
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
urllib3@1.26.2
1.26.5
1
quay.io/kiwigrid/k8s-sidecar:1.10.718feb3906286
urllib3@1.25.11
1.26.5
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
python-pip@20.0.2-5ubuntu1.1
20.0.2-5ubuntu1.7
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.