CVE Tools

Urllib3

19 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Urllib3, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Urllib3 CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Urllib3 CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-062
2025-070
2025-080
2025-090
2025-100
2025-110
2025-122
2026-011
2026-020
2026-030
2026-040
2026-052
2026-060
2026-070
2026-080
2026-090

Severity

How the 19 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical15%
  • High737%
  • Medium1053%
  • Low15%

Latest CVEs

The 15 most recently published vulnerabilities affecting Urllib3.

  1. CVE-2026-44431urllib3: Sensitive headers forwarded across origins in proxied low-level redirects5.3
  2. CVE-2026-44432urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API7.5
  3. CVE-2026-21441urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)7.5
  4. CVE-2025-66471urllib3 Streaming API improperly handles highly compressed data7.5
  5. CVE-2025-66418urllib3 allows an unbounded number of links in the decompression chain7.5
  6. CVE-2025-50182urllib3 does not control redirects in browsers and Node.js5.3
  7. CVE-2025-50181urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation5.3
  8. CVE-2024-37891Proxy-Authorization request header isn't stripped during cross-origin redirects in urllib34.4
  9. CVE-2023-45803Request body not stripped after redirect in urllib34.2
  10. CVE-2018-25091urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials i...6.1
  11. CVE-2023-43804`Cookie` HTTP header isn't stripped on cross-origin redirects5.9
  12. CVE-2021-33503An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracki...7.5
  13. CVE-2021-28363The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy (if an SSLContext isn'...6.5
  14. CVE-2020-26137urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: ...6.5
  15. CVE-2020-7212The _encode_invalid_chars function in util/url.py in the urllib3 library 1.25.2 through 1.25.7 for Python allows a denial of service (CPU consumption) because of an inefficient algorithm. The perce...7.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store