Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2241582
AlmaLinux
5967
Alpaquita
16176
Alpine
4655
Android
3677
Azure Linux
17971
BellSoft Hardened Containers
770
Bitnami
9476
Chainguard
1048510
CleanStart
5235
CRAN
14
crates.io
2763
Debian
68963
Echo
7866
GHC
3
GIT
109042
GitHub Actions
55
Go
9328
Hackage
33
Hex
364
Julia
1713
Linux
29975
Mageia
6237
Maven
7050
MinimOS
148513
npm
229196
NuGet
1869
opam
29
openEuler
8900
openSUSE
14573
OSS-Fuzz
4018
Packagist
7101
Pub
11
PyPI
25464
Red Hat
23527
Rocky Linux
4343
Root
19638
RubyGems
5331
SUSE
23442
SwiftURL
60
TuxCare
9919
Ubuntu
65977
VSCode
21
Wolfi
293807
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-4176
PyPI/urllib3
urllib3: Chunked Deflate streaming can enter an infinite loop
3 days ago
Fix available
Severity - 6.9 (Medium)
PYSEC-2026-4177
PyPI/urllib3
urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory
3 days ago
Fix available
Severity - 8.9 (High)
PYSEC-2026-4175
PyPI/urllib3
urllib3: HTTPS proxy TLS configuration may be ignored or overridden
3 days ago
Fix available
Severity - 7.6 (High)
GHSA-gh4c-6fx4-qh6g
PyPI/urllib3
urllib3: Chunked Deflate streaming can enter an infinite loop
4 days ago
Fix available
Severity - 6.9 (Medium)
GHSA-vxq7-64xx-v4gw
PyPI/urllib3
urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory
4 days ago
Fix available
Severity - 8.9 (High)
GHSA-8988-9cw3-xx77
PyPI/urllib3
urllib3: HTTPS proxy TLS configuration may be ignored or overridden
4 days ago
Fix available
Severity - 7.6 (High)
PYSEC-2026-1996
PyPI/urllib3
Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
07 Jul
Fix available
Severity - 8.9 (High)
PYSEC-2026-1994
PyPI/urllib3
urllib3 streaming API improperly handles highly compressed data
07 Jul
Fix available
Severity - 8.9 (High)
PYSEC-2026-1998
PyPI/urllib3
urllib3 allows an unbounded number of links in the decompression chain
07 Jul
Fix available
Severity - 8.9 (High)
PYSEC-2026-1997
PyPI/urllib3
urllib3 does not control redirects in browsers and Node.js
07 Jul
Fix available
Severity - 5.3 (Medium)
PYSEC-2026-1999
PyPI/urllib3
urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation
07 Jul
Fix available
Severity - 5.3 (Medium)
PYSEC-2026-1995
PyPI/urllib3
urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects
07 Jul
Fix available
Severity - 4.4 (Medium)
PYSEC-2026-142
PyPI/urllib3
See record for full details
13 May
Fix available
Severity - 7.5 (High)
PYSEC-2026-141
PyPI/urllib3
See record for full details
13 May
Fix available
Severity - 5.3 (Medium)
GHSA-mf9v-mfxr-j63j
PyPI/urllib3
urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API
11 May
Fix available
Severity - 8.9 (High)
GHSA-qccp-gfcp-xxvc
PyPI/urllib3
urllib3: Sensitive headers forwarded across origins in proxied low-level redirects
11 May
Fix available
Severity - 8.2 (High)
Load more...
PyPI - OSV