Python / Urllib3
19 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-44431 | urllib3: Sensitive headers forwarded across origins in proxied low-level redirects | HIGH | 8.2 | May 13, 2026 |
| CVE-2026-44432 | urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API | HIGH | 8.9 | May 13, 2026 |
| CVE-2026-21441 | urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) | HIGH | 8.9 | Jan 7, 2026 |
| CVE-2025-66471 | urllib3 Streaming API improperly handles highly compressed data | HIGH | 8.9 | Dec 5, 2025 |
| CVE-2025-66418 | urllib3 allows an unbounded number of links in the decompression chain | HIGH | 8.9 | Dec 5, 2025 |
| CVE-2025-50182 | urllib3 does not control redirects in browsers and Node.js | MEDIUM | 6.1 | Jun 19, 2025 |
| CVE-2025-50181 | urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation | MEDIUM | 6.1 | Jun 19, 2025 |
| CVE-2024-37891 | Proxy-Authorization request header isn't stripped during cross-origin redirects in urllib3 | MEDIUM | 6.5 | Jun 17, 2024 |
| CVE-2023-45803 | Request body not stripped after redirect in urllib3 | MEDIUM | 5.7 | Oct 17, 2023 |
| CVE-2018-25091 | urllib3: urllib3 does not remove the authorization HTTP header when following a cross-origin redirect | MEDIUM | 5.3 | Oct 15, 2023 |
| CVE-2023-43804 | `Cookie` HTTP header isn't stripped on cross-origin redirects | HIGH | 7.4 | Oct 4, 2023 |
| CVE-2021-33503 | python-urllib3: ReDoS in the parsing of authority part of URL | HIGH | 8.7 | Jun 29, 2021 |
| CVE-2021-28363 | python-urllib3: HTTPS proxy host name not validated when using default SSLContext | MEDIUM | 6.9 | Mar 15, 2021 |
| CVE-2020-26137 | python-urllib3: CRLF injection via HTTP request method | MEDIUM | 6.9 | Sep 29, 2020 |
| CVE-2020-7212 | python-urllib3: inefficient algorithm allows a DoS (CPU consumption) in _encode_invalid_chars function in util/url.py | HIGH | 8.7 | Mar 6, 2020 |
| CVE-2019-11324 | python-urllib3: Certification mishandle when error should be thrown | HIGH | 8.7 | Apr 18, 2019 |
| CVE-2019-11236 | python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service | MEDIUM | 5.3 | Apr 15, 2019 |
| CVE-2018-20060 | python-urllib3: Cross-host redirect does not remove Authorization header allow for credential exposure | CRITICAL | 9.3 | Dec 11, 2018 |
| CVE-2016-9015 | Versions 1.17 and 1.18 of the Python urllib3 library suffer from a vulnerability that can cause them, in certain configurations, to not correctly validate TLS… | MEDIUM | 6.3 | Jan 11, 2017 |
Showing 1 to 19 of 19 CVEs