Vulnerabilities
Last updated 1 hour ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
urllib3 streaming API improperly handles highly compressed data | High Risk 8.0 | 9 months ago | 3 days ago |
|
|
urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API | High Risk 7.5 | 4 months ago | 18 days ago |
|
|
urllib3 allows an unbounded number of links in the decompression chain | High Risk 8.0 | 9 months ago | 18 days ago |
|
|
urllib3: Sensitive headers forwarded across origins in proxied low-level redirects | Medium Risk 5.3 | 4 months ago | 18 days ago |
|
|
Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API) | High Risk 7.5 | 8 months ago | 18 days ago |
|
|
urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation | Medium Risk 5.3 | 1 year ago | 18 days ago |
|
|
urllib3 does not control redirects in browsers and Node.js | Medium Risk 5.3 | 1 year ago | 18 days ago |
|
|
urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects | Medium Risk 4.4 | 2 years ago | 18 days ago |
|
|
urllib3's request body not stripped after redirect from 303 status changes request method to GET | Medium Risk 4.2 | 2 years ago | 18 days ago |
|
|
`Cookie` HTTP header isn't stripped on cross-origin redirects | Medium Risk 5.9 | 2 years ago | 18 days ago |
|
|
Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection | Medium Risk 6.5 | 5 years ago | 2 months ago |
|
|
Catastrophic backtracking in URL authority parser when passed URL containing many @ characters | High Risk 7.5 | 5 years ago | 2 months ago |
|
|
urllib3 streaming API improperly handles highly compressed data | Unknown | 2 months ago | 2 months ago |
|
|
urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects | Medium Risk 4.4 | 2 months ago | 2 months ago |
|
|
Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API) | High Risk 7.5 | 2 months ago | 2 months ago |
|
|
urllib3 does not control redirects in browsers and Node.js | Medium Risk 5.3 | 2 months ago | 2 months ago |
|
|
urllib3 allows an unbounded number of links in the decompression chain | Unknown | 2 months ago | 2 months ago |
|
|
urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation | Medium Risk 5.3 | 2 months ago | 2 months ago |
|
|
No summary available | Unknown | 9 years ago | 3 months ago |
|
|
No summary available | Medium Risk 6.1 | 2 years ago | 3 months ago |
|
|
No summary available | Unknown | 5 years ago | 3 months ago |
|
|
No summary available | High Risk 7.5 | 4 months ago | 4 months ago |
|
|
No summary available | Medium Risk 5.3 | 4 months ago | 4 months ago |
|
|
Exposure of Sensitive Information to an Unauthorized Actor in urllib3 | Critical 9.8 | 7 years ago | 1 year ago |
|
|
Authorization Header forwarded on redirect | Medium Risk 6.1 | 2 years ago | 1 year ago |
|
|
Urllib3 Incorrect Certificate Validation | Low Risk 3.7 | 4 years ago | 1 year ago |
|
|
Improper Neutralization of CRLF Sequences in urllib3 library for Python | Medium Risk 6.1 | 4 years ago | 1 year ago |
|
|
CRLF injection in urllib3 | Medium Risk 6.5 | 5 years ago | 1 year ago |
|
|
Uncontrolled Resource Consumption in urllib3 | High Risk 7.5 | 5 years ago | 1 year ago |
|
|
Improper Certificate Validation in urllib3 | High Risk 7.5 | 7 years ago | 1 year ago |
|
|
Malicious code in urllib33 (PyPI) | Unknown | 2 years ago | 1 year ago |
|
|
No summary available | Medium Risk 4.2 | 2 years ago | 2 years ago |
|
|
No summary available | High Risk 8.1 | 2 years ago | 2 years ago |
|
|
No summary available | Unknown | 5 years ago | 2 years ago |
|
|
No summary available | Unknown | 6 years ago | 2 years ago |
|
|
No summary available | Unknown | 5 years ago | 2 years ago |
|
|
No summary available | Unknown | 7 years ago | 2 years ago |
|
|
No summary available | Unknown | 7 years ago | 2 years ago |
|
|
No summary available | Unknown | 7 years ago | 2 years ago |
|
|
Malicious code in uurllib3 (PyPI) | Unknown | 3 years ago | 3 years ago |
Page 1