CVE-2021-29462

high
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
8.0

Description

The Portable SDK for UPnP Devices is an SDK for development of UPnP device and control point applications. The server part of pupnp (libupnp) appears to be vulnerable to DNS rebinding attacks because it does not check the value of the `Host` header. This can be mitigated by using DNS revolvers which block DNS-rebinding attacks. The vulnerability is fixed in version 1.14.6 and later.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2021-29462

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-202104-8

OS impact

OSVersionStatusFixed in
arch archfixed1.14.6-1
debian debianforkyfixed0
debian debiansidfixed0
debian debianbookwormaffected
debian debianbullseyeaffected
debian debiantrixiefixed0

References

Verify integrity in audit chain (admin only). AS-IS.