Known Vulnerabilities for Urllib by Node-modules
Listed below are 10 of the newest known vulnerabilities associated with "Urllib" by "Node-modules".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-92184 json | A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. Affected is the function urllib.request.urlopen of the fil... | Not Provided | 2026-09-16 | 2026-09-17 |
| CVE-2026-82397 json | Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-... | Not Provided | 2026-08-31 | 2026-09-02 |
| CVE-2026-79785 json | X-AnyLabeling's model downloader disabled TLS certificate verification. download_with_retry in anylabeling/services/auto_labe... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-67201 json | V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows atta... | Not Provided | 2026-07-29 | 2026-07-29 |
| CVE-2026-55553 json | urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features. Prior to ... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-55524 json | PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the ... | Not Provided | 2026-08-05 | 2026-08-06 |
| CVE-2026-55185 json | Miniflux 2 is an open source feed reader. Prior to 2.3.1, IsRelativePath in internal/urllib/url.go accepts redirect targets c... | Not Provided | 2026-08-21 | 2026-08-24 |
| CVE-2026-54915 json | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the unauthenticated /auth/red... | Not Provided | 2026-09-21 | 2026-09-21 |
| CVE-2026-54770 json | WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob/resp... | Not Provided | 2026-08-20 | 2026-08-25 |
| CVE-2026-47395 json | PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiag... | Not Provided | 2026-07-21 | 2026-07-21 |