CVE-2021-33580
NixOS vulnerability analysis and mitigation

Overview

CVE-2021-33580 is a regex injection vulnerability discovered in Apache Roller that can lead to Denial of Service (DoS). The vulnerability was disclosed on August 17, 2021, and affects Apache Roller installations where Banned-words Referrer processing is enabled, though this feature is disabled by default (Openwall Report).

Technical details

The vulnerability stems from user-controlled input fields including request.getHeader("Referer"), request.getRequestURL(), and request.getQueryString() being used to build and execute regex expressions. An attacker can exploit this by sending specially crafted Referer headers programmatically, potentially causing Regular Expression Denial of Service (ReDoS) through regex catastrophic backtracking on the server side. The vulnerability is classified as CWE-400 (NVD Report).

Impact

The primary impact of this vulnerability is the potential for Denial of Service attacks against Apache Roller servers that have Banned-words Referrer processing enabled. The severity is classified as Low since the vulnerable feature is disabled by default (Openwall Report).

Mitigation and workarounds

The vulnerability has been patched in Apache Roller version 6.0.2. For users unable to upgrade, a workaround is available by disabling the Banned-Words Referrer processing feature by setting the property 'site.bannedwordslist.enable.referrers=false' in the Roller properties (Openwall Report).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-14330CRITICAL9.8
  • NixOSNixOS
  • rhel10::firefox-flatpak
NoYesDec 09, 2025
CVE-2025-14329HIGH8.8
  • NixOSNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesDec 09, 2025
CVE-2025-14333HIGH8.1
  • NixOSNixOS
  • firefox
NoYesDec 09, 2025
CVE-2025-14332HIGH7.3
  • NixOSNixOS
  • cpe:2.3:a:mozilla:firefox
NoYesDec 09, 2025
CVE-2025-14331MEDIUM6.5
  • NixOSNixOS
  • rhel10::thunderbird-flatpak
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management