Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

pypi urllib3 Security Advisories

Loading...
Moderate
GSA_kwCzR0hTQS0zNGpoLXA5N2YtbXB4Zs4AA9I1
urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects
Ecosystems: pypi
Packages: urllib3
Source: GitHub Advisory Database
Blast Radius: 24.8
Published: about 1 month ago
Moderate
GSA_kwCzR0hTQS1nNG14LXE5dmctMjdwNM4AA2gt
urllib3's request body not stripped after redirect from 303 status changes request method to GET
Ecosystems: pypi
Packages: urllib3
Source: GitHub Advisory Database
Blast Radius: 23.6
Published: 9 months ago
Moderate
GSA_kwCzR0hTQS1nd3ZtLTQ1Z3gtM2NmOM4AA2c6
Authorization Header forwarded on redirect
Ecosystems: pypi
Packages: urllib3
Source: GitHub Advisory Database
Blast Radius: 34.3
Published: 9 months ago
Moderate
GSA_kwCzR0hTQS12ODQ1LWp4eDUtdmM5Zs4AA2MD
`Cookie` HTTP header isn't stripped on cross-origin redirects
Ecosystems: pypi
Packages: urllib3
Source: GitHub Advisory Database
Blast Radius: 33.2
Published: 10 months ago
Low
GSA_kwCzR0hTQS12NHc1LXAyaGctOGZoNs4AAcGU
Urllib3 Incorrect Certificate Validation
Ecosystems: pypi
Packages: urllib3
Source: GitHub Advisory Database
Blast Radius: 20.8
Published: about 2 years ago
Moderate
GSA_kwCzR0hTQS1yNjRxLXc4anItZzlxcM3wRw
Improper Neutralization of CRLF Sequences in urllib3 library for Python
Ecosystems: pypi
Packages: urllib3
Source: GitHub Advisory Database
Blast Radius: 34.3
Published: about 2 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXdxdnEtNW04Yy02ZzI0
CRLF injection in urllib3
Ecosystems: pypi
Packages: urllib3
Source: GitHub Advisory Database
Blast Radius: 36.6
Published: about 3 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXEycTctNXBwNC13NnBn
Catastrophic backtracking in URL authority parser when passed URL containing many @ characters
Ecosystems: pypi
Packages: urllib3
Source: GitHub Advisory Database
Blast Radius: 42.2
Published: about 3 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWhtdjItNzlxOC1mdjZn
Uncontrolled Resource Consumption in urllib3
Ecosystems: pypi
Packages: urllib3
Source: GitHub Advisory Database
Blast Radius: 42.2
Published: about 3 years ago
Moderate
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTVwaGYtcHA3cC12YzJy
Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection
Ecosystems: pypi
Packages: urllib3
Source: GitHub Advisory Database
Blast Radius: 36.6
Published: over 3 years ago
High
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW1oMzMtN3JycS02NjJ3
Improper Certificate Validation in urllib3
Ecosystems: pypi
Packages: urllib3
Source: GitHub Advisory Database
Blast Radius: 42.2
Published: about 5 years ago
Critical
MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXd3dzItdjd4ai14cmM2
Exposure of Sensitive Information to an Unauthorized Actor in urllib3
Ecosystems: pypi
Packages: urllib3
Source: GitHub Advisory Database
Blast Radius: 55.1
Published: over 5 years ago
Statistics
Advisories: 19,517
Packages: 8,615
Repositories: 1
Ecosystems: 12
Filter by Package
tensorflow 432 tensorflow-cpu 387 tensorflow-gpu 384 apache-airflow 82 django 80 ansible 63 salt 55 Plone 52 apache-superset 51 nova 47 mlflow 46 plone 43 rdiffweb 42 Pillow 41 vyper 38 Django 36 matrix-synapse 35 moin 35 keystone 31 opencv-python 30 opencv-contrib-python 30 glance 20 langchain 19 gradio 18 PaddlePaddle 17 mercurial 17 cobbler 17 neutron 16 pillow 16 cryptography 15 notebook 15 paddlepaddle 15 modoboa 14 pyload-ng 14 pyftpdlib 14 ethyca-fides 13 OctoPrint 13 vantage6 13 wagtail 12 urllib3 12 swift 12 zenml 11 onionshare-cli 11 horizon 11 aiohttp 11 twisted 11 calibreweb 11 nautobot 10 trytond 10 Flask-AppBuilder 10 waitress 9 roundup 9 opencv-python-headless 9 opencv-contrib-python-headless 9 zope 9 cinder 9 ryu 9 Zope 9 kiwitcms 9 label-studio 8 python-keystoneclient 8 numpy 8 trac 8 aubio 8 matrix-sydent 7 sentry 7 lief 7 jupyter-server 7 lollms 7 ipython 7 pysaml2 7 pip 7 pgadmin4 7 litellm 7 scrapy 7 apache-airflow-providers-apache-hive 6 lxml 6 yt-dlp 6 Zope2 6 tuf 6 mindsdb 6 inventree 6 Moin 6 graphite-web 6 tornado 6 web2py 6 mailman 6 requests 6 Products.CMFPlone 5 whoogle-search 5 saleor 5 ckan 5 pyspark 5 omero-web 5 nltk 5 bleach 5 feedparser 5 oauthenticator 5 paramiko 5 Jinja2 5 lmdb 5 python-gnupg 5 PyPDF2 4 GitPython 4 buildbot 4 dbt-core 4 keylime 4 markdown2 4 langchain-experimental 4 Werkzeug 4 httpie 4 Keystone 4 Pygments 4 Scrapy 4 Radicale 4 nvflare 4 Flask-Security-Too 4 FreeTAKServer-UI 4 reportlab 4 jupyterhub 4 barbican 4 qutebrowser 4 transformers 4 werkzeug 4 tripleo-heat-templates 4 starlette 4 pretix 4 software.amazon.awssdk.iotdevicesdk:aws-iot-device-sdk 4 aws-iot-device-sdk-v2 4 ansible-core 4 awsiotsdk 4 datasette 4 Weblate 4 grpcio 4 grpc 4 bottle 4 jwcrypto 4 esphome 4 django-helpdesk 3 onnx 3 copyparty 3 Nova 3 homeassistant 3 Red-DiscordBot 3 apache-iotdb 3 python-jose 3 jupyterlab 3 poetry 3 localstack 3 streamlit 3 plone.supermodel 3 mistune 3 plone.app.dexterity 3 plone.app.theming 3 plone.app.event 3 io.grpc:grpc-protobuf 3 changedetection.io 3 jupyter-server-proxy 3 apache-airflow-providers-apache-spark 3 pyarrow 3 setuptools 3 pyyaml 3 asyncssh 3 SQLAlchemy 3 ray 3 apache-libcloud 3 Kallithea 3 flask 3 ujson 3 fava 3 Mezzanine 3 sickrage 3 sosreport 3 httplib2 3 vanna 3 sqlparse 3 rsa 3 torchserve 3 ydata-profiling 3 openvpn-monitor 3 slixmpp 3 octavia 3 dtale 3 gerapy 3 scikit-learn 3 bitlyshortener 3 ajenti 3 mayan-edms 3 pandasai 3 ecdsa 3 llama-index 3 pywasm3 3 indico 3 dulwich 3 keystonemiddleware 3 django-tinymce 3 TinyMCE 3 Products.PluggableAuthService 3 ansible-runner 3 tinymce 3