Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2199629
AlmaLinux
5919
Alpaquita
15755
Alpine
4608
Android
3674
Azure Linux
17638
BellSoft Hardened Containers
746
Bitnami
9290
Chainguard
1023665
CleanStart
3591
CRAN
14
crates.io
2732
Debian
68367
Echo
7421
GHC
3
GIT
108119
GitHub Actions
55
Go
9203
Hackage
32
Hex
361
Julia
1713
Linux
29974
Mageia
6227
Maven
7040
MinimOS
144419
npm
228744
NuGet
1869
opam
29
openEuler
8800
openSUSE
14455
OSS-Fuzz
4013
Packagist
7095
Pub
11
PyPI
25166
Red Hat
23331
Rocky Linux
4297
Root
19535
RubyGems
5326
SUSE
23168
SwiftURL
60
TuxCare
9512
Ubuntu
65370
VSCode
21
Wolfi
288261
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-1996
PyPI/urllib3
Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
07 Jul
Fix available
Severity - 8.9 (High)
PYSEC-2026-1994
PyPI/urllib3
urllib3 streaming API improperly handles highly compressed data
07 Jul
Fix available
Severity - 8.9 (High)
PYSEC-2026-1998
PyPI/urllib3
urllib3 allows an unbounded number of links in the decompression chain
07 Jul
Fix available
Severity - 8.9 (High)
PYSEC-2026-1997
PyPI/urllib3
urllib3 does not control redirects in browsers and Node.js
07 Jul
Fix available
Severity - 5.3 (Medium)
PYSEC-2026-1999
PyPI/urllib3
urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation
07 Jul
Fix available
Severity - 5.3 (Medium)
PYSEC-2026-1995
PyPI/urllib3
urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects
07 Jul
Fix available
Severity - 4.4 (Medium)
PYSEC-2026-142
PyPI/urllib3
See record for full details
13 May
Fix available
Severity - 7.5 (High)
PYSEC-2026-141
PyPI/urllib3
See record for full details
13 May
Fix available
Severity - 5.3 (Medium)
GHSA-mf9v-mfxr-j63j
PyPI/urllib3
urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API
11 May
Fix available
Severity - 8.9 (High)
GHSA-qccp-gfcp-xxvc
PyPI/urllib3
urllib3: Sensitive headers forwarded across origins in proxied low-level redirects
11 May
Fix available
Severity - 8.2 (High)
GHSA-38jv-5279-wg99
PyPI/urllib3
Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
07 Jan
Fix available
Severity - 8.9 (High)
GHSA-2xpw-w6gg-jr37
PyPI/urllib3
urllib3 streaming API improperly handles highly compressed data
05 Dec 2025
Fix available
Severity - 8.9 (High)
GHSA-gm62-xv2j-4w53
PyPI/urllib3
urllib3 allows an unbounded number of links in the decompression chain
05 Dec 2025
Fix available
Severity - 8.9 (High)
GHSA-48p4-8xcf-vxj5
PyPI/urllib3
urllib3 does not control redirects in browsers and Node.js
18 Jun 2025
Fix available
Severity - 5.3 (Medium)
GHSA-pq67-6m6q-mj2v
PyPI/urllib3
urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation
18 Jun 2025
Fix available
Severity - 5.3 (Medium)
GHSA-34jh-p97f-mpxf
PyPI/urllib3
urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects
17 Jun 2024
Fix available
Severity - 4.4 (Medium)
Load more...
PyPI - OSV