Known Vulnerabilities for Urllib3 by Python
Listed below are 10 of the newest known vulnerabilities associated with "Urllib3" by "Python".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-45803 json | urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP request body when an H... | 4.2 - MEDIUM | 2023-10-17 | 2023-11-03 |
| CVE-2023-43804 json | urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide ... | 8.1 - HIGH | 2023-10-04 | 2024-02-01 |
| CVE-2021-33503 json | An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority comp... | 7.5 - HIGH | 2021-06-29 | 2023-11-07 |
| CVE-2021-28363 json | The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS p... | 6.5 - MEDIUM | 2021-03-15 | 2023-11-07 |
| CVE-2020-26137 json | urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR... | 6.5 - MEDIUM | 2020-09-30 | 2023-10-08 |
| CVE-2020-7212 json | The _encode_invalid_chars function in util/url.py in the urllib3 library 1.25.2 through 1.25.7 for Python allows a denial of ... | 7.5 - HIGH | 2020-03-06 | 2020-03-09 |
| CVE-2019-11324 json | The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different f... | 7.5 - HIGH | 2019-04-18 | 2023-11-07 |
| CVE-2019-11236 json | In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter. | 6.1 - MEDIUM | 2019-04-15 | 2023-11-07 |
| CVE-2018-25091 json | urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect ... | 6.1 - MEDIUM | 2023-10-15 | 2023-10-19 |
| CVE-2018-20060 json | urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a red... | 9.8 - CRITICAL | 2018-12-11 | 2023-11-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Python | Urllib3 | 1.9.1 | |||
| Application | Python | Urllib3 | 1.9 | |||
| Application | Python | Urllib3 | 1.8.3 | |||
| Application | Python | Urllib3 | 1.8.2 | |||
| Application | Python | Urllib3 | 1.8.1 | |||
| Application | Python | Urllib3 | 1.8 | |||
| Application | Python | Urllib3 | 1.7.1 | |||
| Application | Python | Urllib3 | 1.7 | |||
| Application | Python | Urllib3 | 1.6 | |||
| Application | Python | Urllib3 | 1.5 | |||
| Application | Python | Urllib3 | 1.4 | |||
| Application | Python | Urllib3 | 1.3 | |||
| Application | Python | Urllib3 | 1.25.9 | |||
| Application | Python | Urllib3 | 1.25.8 | |||
| Application | Python | Urllib3 | 1.25.7 | |||
| Application | Python | Urllib3 | 1.25.6 | |||
| Application | Python | Urllib3 | 1.25.5 | |||
| Application | Python | Urllib3 | 1.25.4 | |||
| Application | Python | Urllib3 | 1.25.3 | |||
| Application | Python | Urllib3 | 1.25.2 |