Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2242427
AlmaLinux
5975
Alpaquita
16176
Alpine
4655
Android
3708
Azure Linux
17971
BellSoft Hardened Containers
770
Bitnami
9501
Chainguard
1048512
CleanStart
5432
CRAN
14
crates.io
2768
Debian
68992
Echo
7853
GHC
3
GIT
109057
GitHub Actions
55
Go
9332
Hackage
33
Hex
365
Julia
1713
Linux
29975
Mageia
6237
Maven
7055
MinimOS
148636
npm
229266
NuGet
1869
opam
29
openEuler
8900
openSUSE
14647
OSS-Fuzz
4019
Packagist
7103
Pub
11
PyPI
25495
Red Hat
23535
Rocky Linux
4344
Root
19644
RubyGems
5369
SUSE
23455
SwiftURL
61
TuxCare
9974
Ubuntu
66090
VSCode
21
Wolfi
293807
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-4176
PyPI/urllib3
urllib3: Chunked Deflate streaming can enter an infinite loop
4 days ago
Fix available
Severity - 6.9 (Medium)
PYSEC-2026-4177
PyPI/urllib3
urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory
4 days ago
Fix available
Severity - 8.9 (High)
PYSEC-2026-4175
PyPI/urllib3
urllib3: HTTPS proxy TLS configuration may be ignored or overridden
4 days ago
Fix available
Severity - 7.6 (High)
GHSA-gh4c-6fx4-qh6g
PyPI/urllib3
urllib3: Chunked Deflate streaming can enter an infinite loop
5 days ago
Fix available
Severity - 6.9 (Medium)
GHSA-vxq7-64xx-v4gw
PyPI/urllib3
urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory
5 days ago
Fix available
Severity - 8.9 (High)
GHSA-8988-9cw3-xx77
PyPI/urllib3
urllib3: HTTPS proxy TLS configuration may be ignored or overridden
5 days ago
Fix available
Severity - 7.6 (High)
PYSEC-2026-1996
PyPI/urllib3
Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
07 Jul
Fix available
Severity - 8.9 (High)
PYSEC-2026-1994
PyPI/urllib3
urllib3 streaming API improperly handles highly compressed data
07 Jul
Fix available
Severity - 8.9 (High)
PYSEC-2026-1998
PyPI/urllib3
urllib3 allows an unbounded number of links in the decompression chain
07 Jul
Fix available
Severity - 8.9 (High)
PYSEC-2026-1997
PyPI/urllib3
urllib3 does not control redirects in browsers and Node.js
07 Jul
Fix available
Severity - 5.3 (Medium)
PYSEC-2026-1999
PyPI/urllib3
urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation
07 Jul
Fix available
Severity - 5.3 (Medium)
PYSEC-2026-1995
PyPI/urllib3
urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects
07 Jul
Fix available
Severity - 4.4 (Medium)
PYSEC-2026-142
PyPI/urllib3
See record for full details
13 May
Fix available
Severity - 7.5 (High)
PYSEC-2026-141
PyPI/urllib3
See record for full details
13 May
Fix available
Severity - 5.3 (Medium)
GHSA-mf9v-mfxr-j63j
PyPI/urllib3
urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API
11 May
Fix available
Severity - 8.9 (High)
GHSA-qccp-gfcp-xxvc
PyPI/urllib3
urllib3: Sensitive headers forwarded across origins in proxied low-level redirects
11 May
Fix available
Severity - 8.2 (High)
Load more...
PyPI - OSV