VulnSea

urllib3 vulnerabilities

CVEs whose affected-version data names the urllib3 package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

9 CVEsRSS

CVE-2026-44432High· 7.5
4mo ago

urllib3 is an HTTP client library for Python

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed…

Twilightpython · urllib3EPSS 0.68%via NVD
CVE-2026-21441High· 7.5
8mo ago

urllib3 is an HTTP client library for Python

urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urll…

Twilightpython · urllib3EPSS 3.0%via NVD
CVE-2025-66418High
9mo ago

urllib3 allows an unbounded number of links in the decompression chain

urllib3 allows an unbounded number of links in the decompression chain

Twilighturllib3 · urllib3EPSS 0.68%via OSV
CVE-2025-66471High
9mo ago

urllib3 streaming API improperly handles highly compressed data

urllib3 streaming API improperly handles highly compressed data

Twilighturllib3 · urllib3EPSS 0.68%via OSV
CVE-2024-37891Medium· 4.4
2y ago

urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects

urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects

Sunliturllib3 · urllib3EPSS 1.1%via OSV
CVE-2023-45803Medium· 4.2
2y ago

urllib3's request body not stripped after redirect from 303 status changes request method to GET

urllib3's request body not stripped after redirect from 303 status changes request method to GET

Sunliturllib3 · urllib3EPSS 0.54%via OSV
CVE-2023-43804Medium· 5.9PoC
2y ago

`Cookie` HTTP header isn't stripped on cross-origin redirects

`Cookie` HTTP header isn't stripped on cross-origin redirects

Twilighturllib3 · urllib3EPSS 1.2%via OSV
CVE-2021-33503High· 7.5
5y ago

Catastrophic backtracking in URL authority parser when passed URL containing many @ characters

Catastrophic backtracking in URL authority parser when passed URL containing many @ characters

Twilighturllib3 · urllib3EPSS 3.3%via OSV
CVE-2021-28363Medium· 6.5
5y ago

Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection

Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection

Sunliturllib3 · urllib3EPSS 2.1%via OSV
urllib3 vulnerabilities (CVEs) · VulnSea