Package impact

python PyPI / urllib3

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2025-66418 high 8.0 4mo ago Important: python-urllib3 security update rockylinuxredhatsusedebian+1
CVE-2026-21441 high 8.0 5mo ago Important: python-urllib3 security update rockylinuxredhatsusedebian+1
CVE-2025-66471 high 8.0 6mo ago Important: python-urllib3 security update rockylinuxredhatsusedebian+1
CVE-2021-28363 high 8.0 5y ago The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy (if an SSLContext isn't … archsusedebianpython
CVE-2026-44432 high 7.5 7.5 14d ago urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) c… susedebianpython
CVE-2024-37891 medium 5.5 2y ago Moderate: python-urllib3 security update redhatrockylinuxsusedebian+1
CVE-2023-45803 medium 5.5 2y ago Moderate: python-urllib3 security update redhatrockylinuxsusedebian+1
CVE-2023-43804 medium 5.5 3y ago Moderate: python39:3.9 and python39-devel:3.9 security update redhatrockylinuxsusedebian+1
CVE-2019-11236 medium 5.5 4y ago Moderate: python27:2.7 security, bug fix, and enhancement update rockylinuxdebianpython
CVE-2020-26137 medium 5.5 5y ago Moderate: python27:2.7 security and bug fix update suserockylinuxdebianpython
CVE-2021-33503 medium 5.5 5y ago Moderate: python38:3.8 and python38-devel:3.8 security update archsuserockylinuxdebian+1
CVE-2019-11324 medium 5.5 7y ago Moderate: python27:2.7 security, bug fix, and enhancement update suserockylinuxdebianpython
CVE-2018-20060 medium 5.5 8y ago Moderate: python27:2.7 security, bug fix, and enhancement update suserockylinuxdebianpython
CVE-2026-44431 medium 5.3 5.3 14d ago urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=Fa… susedebianpythongcp
CVE-2016-9015 low 3.7 3.7 10y ago Versions 1.17 and 1.18 of the Python urllib3 library suffer from a vulnerability that can cause them, in certain configurations, to not correctly validate TLS certificates. This places users of the l… susedebianpython
CVE-2025-50182 unknown 11mo ago urllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does not control redirects in browsers and Node.js. urllib3 supports being used in a P… susedebianpython
CVE-2025-50181 unknown 11mo ago urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation susedebianpython
CVE-2018-25091 unknown 3y ago urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in … susedebianpython
CVE-2020-7212 unknown 5y ago The _encode_invalid_chars function in util/url.py in the urllib3 library 1.25.2 through 1.25.7 for Python allows a denial of service (CPU consumption) because of an inefficient algorithm. The percent… debianpython