VendorsPythonurllib3all versions
Vulnerabilities

Python urllib3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19CVEs
CVE-2018-20060
urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.
Published 2018-12-11 · Modified
9.8EPSS 0.045
CVE-2026-21441
urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
Published 2026-01-07 · Modified
8.9EPSS 0.030
CVE-2025-66471
urllib3 Streaming API improperly handles highly compressed data
Published 2025-12-05 · Analyzed
8.9EPSS 0.007
CVE-2025-66418
urllib3 allows an unbounded number of links in the decompression chain
Published 2025-12-05 · Analyzed
8.9EPSS 0.007
CVE-2026-44432
urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API
Published 2026-05-13 · Modified
8.9EPSS 0.007
CVE-2026-44431
urllib3: Sensitive headers forwarded across origins in proxied low-level redirects
Published 2026-05-13 · Modified
8.2EPSS 0.003
CVE-2023-43804
`Cookie` HTTP header isn't stripped on cross-origin redirects
Published 2023-10-04 · Modified
8.1EPSS 0.012
CVE-2020-7212
The _encode_invalid_chars function in util/url.py in the urllib3 library 1.25.2 through 1.25.7 for Python allows a denial of service (CPU consumption) because of an inefficient algorithm. The percent_encodings array contains all matches of percent encodings. It is not deduplicated. For a URL of length N, the size of percent_encodings may be up to O(N). The next step (normalize existing percent-encoded bytes) also takes up to O(N) for each step, so the total time is O(N^2). If percent_encodings were deduplicated, the time to compute _encode_invalid_chars would be O(kN), where k is at most 484 ((10+6*2)^2).
Published 2020-03-06 · Modified
7.8EPSS 0.034
CVE-2021-33503
An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.
Published 2021-06-29 · Modified
7.5EPSS 0.033
CVE-2019-11324
The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in SSL connections succeeding in situations where a verification failure is the correct outcome. This is related to use of the ssl_context, ca_certs, or ca_certs_dir argument.
Published 2019-04-18 · Modified
7.5EPSS 0.028
CVE-2020-26137
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
Published 2020-09-29 · Modified
6.5EPSS 0.023
CVE-2021-28363
The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy (if an SSLContext isn't given via proxy_config) doesn't verify the hostname of the certificate. This means certificates for different servers that still validate properly with the default urllib3 SSLContext will be silently accepted.
Published 2021-03-15 · Modified
6.5EPSS 0.021
CVE-2024-37891
Proxy-Authorization request header isn't stripped during cross-origin redirects in urllib3
Published 2024-06-17 · Analyzed
6.5EPSS 0.011
CVE-2019-11236
In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.
Published 2019-04-15 · Modified
6.1EPSS 0.021
CVE-2018-25091
urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the authorization header to be exposed to unintended hosts or transmitted in cleartext. NOTE: this issue exists because of an incomplete fix for CVE-2018-20060 (which was case-sensitive).
Published 2023-10-15 · Modified
6.1EPSS 0.005
CVE-2025-50181
urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation
Published 2025-06-19 · Modified
6.1EPSS 0.005
CVE-2025-50182
urllib3 does not control redirects in browsers and Node.js
Published 2025-06-19 · Modified
6.1EPSS 0.004
CVE-2023-45803
Request body not stripped after redirect in urllib3
Published 2023-10-17 · Modified
4.2EPSS 0.005
CVE-2016-9015
Versions 1.17 and 1.18 of the Python urllib3 library suffer from a vulnerability that can cause them, in certain configurations, to not correctly validate TLS certificates. This places users of the library with those configurations at risk of man-in-the-middle and information leakage attacks. This vulnerability affects users using versions 1.17 and 1.18 of the urllib3 library, who are using the optional PyOpenSSL support for TLS instead of the regular standard library TLS backend, and who are using OpenSSL 1.1.0 via PyOpenSSL. This is an extremely uncommon configuration, so the security impact of this vulnerability is low.
Published 2017-01-11 · Modified
3.7EPSS 0.008