Known Vulnerabilities for Urllib by Node-modules
Listed below are 10 of the newest known vulnerabilities associated with "Urllib" by "Node-modules".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-82397 json | Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-... | Not Provided | 2026-08-31 | 2026-08-31 |
| CVE-2026-79785 json | X-AnyLabeling's model downloader disabled TLS certificate verification. download_with_retry in anylabeling/services/auto_labe... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-67201 json | V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows atta... | Not Provided | 2026-07-29 | 2026-07-29 |
| CVE-2026-55553 json | urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features. Prior to ... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-55524 json | PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the ... | Not Provided | 2026-08-05 | 2026-08-06 |
| CVE-2026-55185 json | Miniflux 2 is an open source feed reader. Prior to 2.3.1, IsRelativePath in internal/urllib/url.go accepts redirect targets c... | Not Provided | 2026-08-21 | 2026-08-24 |
| CVE-2026-54770 json | WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob/resp... | Not Provided | 2026-08-20 | 2026-08-25 |
| CVE-2026-53872 json | picklescan before 0.0.35 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to read a... | Not Provided | 2026-06-17 | 2026-06-17 |
| CVE-2026-53538 json | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separato... | Not Provided | 2026-06-22 | 2026-06-23 |
| CVE-2026-47395 json | PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiag... | Not Provided | 2026-07-21 | 2026-07-21 |