Package impact

python PyPI / urllib3

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2025-66418 high 8.0 4mo ago Important: python-urllib3 security update rockylinuxredhatsusedebian+1
CVE-2026-21441 high 8.0 5mo ago Important: python-urllib3 security update rockylinuxredhatsusedebian+1
CVE-2025-66471 high 8.0 6mo ago Important: python-urllib3 security update rockylinuxredhatsusedebian+1
CVE-2021-28363 high 8.0 5y ago The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy (if an SSLContext isn't … archsusedebianpython
CVE-2026-44432 high 7.5 7.5 15d ago urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) c… susedebianpython
CVE-2016-9015 low 3.7 3.7 10y ago Versions 1.17 and 1.18 of the Python urllib3 library suffer from a vulnerability that can cause them, in certain configurations, to not correctly validate TLS certificates. This places users of the l… susedebianpython