Urllib3
19 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Urllib3, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Urllib3 CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 2 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 2 |
| 2026-01 | 1 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 2 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 19 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High7
- Medium10
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Urllib3.
- CVE-2026-44431urllib3: Sensitive headers forwarded across origins in proxied low-level redirects5.3
- CVE-2026-44432urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API7.5
- CVE-2026-21441urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)7.5
- CVE-2025-66471urllib3 Streaming API improperly handles highly compressed data7.5
- CVE-2025-66418urllib3 allows an unbounded number of links in the decompression chain7.5
- CVE-2025-50182urllib3 does not control redirects in browsers and Node.js5.3
- CVE-2025-50181urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation5.3
- CVE-2024-37891Proxy-Authorization request header isn't stripped during cross-origin redirects in urllib34.4
- CVE-2023-45803Request body not stripped after redirect in urllib34.2
- CVE-2018-25091urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials i...6.1
- CVE-2023-43804`Cookie` HTTP header isn't stripped on cross-origin redirects5.9
- CVE-2021-33503An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracki...7.5
- CVE-2021-28363The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy (if an SSLContext isn'...6.5
- CVE-2020-26137urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: ...6.5
- CVE-2020-7212The _encode_invalid_chars function in util/url.py in the urllib3 library 1.25.2 through 1.25.7 for Python allows a denial of service (CPU consumption) because of an inefficient algorithm. The perce...7.5
Product grouping is registry-driven, with AI assist and human review. How it works