Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-1996
  • PyPI/urllib3
Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API) 07 Jul
  • Fix available
  • Severity - 8.9 (High)
PYSEC-2026-1994
  • PyPI/urllib3
urllib3 streaming API improperly handles highly compressed data 07 Jul
  • Fix available
  • Severity - 8.9 (High)
PYSEC-2026-1998
  • PyPI/urllib3
urllib3 allows an unbounded number of links in the decompression chain 07 Jul
  • Fix available
  • Severity - 8.9 (High)
PYSEC-2026-1997
  • PyPI/urllib3
urllib3 does not control redirects in browsers and Node.js 07 Jul
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-1999
  • PyPI/urllib3
urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation 07 Jul
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-1995
  • PyPI/urllib3
urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects 07 Jul
  • Fix available
  • Severity - 4.4 (Medium)
PYSEC-2026-142
  • PyPI/urllib3
See record for full details 13 May
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-141
  • PyPI/urllib3
See record for full details 13 May
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-mf9v-mfxr-j63j
  • PyPI/urllib3
urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API 11 May
  • Fix available
  • Severity - 8.9 (High)
GHSA-qccp-gfcp-xxvc
  • PyPI/urllib3
urllib3: Sensitive headers forwarded across origins in proxied low-level redirects 11 May
  • Fix available
  • Severity - 8.2 (High)
GHSA-38jv-5279-wg99
  • PyPI/urllib3
Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API) 07 Jan
  • Fix available
  • Severity - 8.9 (High)
GHSA-2xpw-w6gg-jr37
  • PyPI/urllib3
urllib3 streaming API improperly handles highly compressed data 05 Dec 2025
  • Fix available
  • Severity - 8.9 (High)
GHSA-gm62-xv2j-4w53
  • PyPI/urllib3
urllib3 allows an unbounded number of links in the decompression chain 05 Dec 2025
  • Fix available
  • Severity - 8.9 (High)
GHSA-48p4-8xcf-vxj5
  • PyPI/urllib3
urllib3 does not control redirects in browsers and Node.js 18 Jun 2025
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-pq67-6m6q-mj2v
  • PyPI/urllib3
urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation 18 Jun 2025
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-34jh-p97f-mpxf
  • PyPI/urllib3
urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects 17 Jun 2024
  • Fix available
  • Severity - 4.4 (Medium)