Urllib3

Vendor:

First CVE: Jan 11, 2017 · Active for 9 years

19
Total CVEs
More Total CVEs than 93% of tracked products
2.1
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 35% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Urllib3 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 11, 2017
9 years ago
Most Recent CVE
May 13, 2026
74 days ago

CVE Severity & Scoring

Urllib319 CVEs
All CVEs352,719 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (94.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (5.3%)
Attack Complexity
Low17 (89.5%)
High2 (10.5%)
Unknown0 (0.0%)
User Interaction
None15 (78.9%)
Unknown0 (0.0%)
Required4 (21.1%)
Privileges Required
Low2 (10.5%)
High1 (5.3%)
None16 (84.2%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPRes
May 13, 20267.538NONO
urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than l
Jan 7, 20267.533NONO
urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can
Dec 11, 20189.833NONO
urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(...,
May 13, 20265.331NONO
urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a mali
Dec 5, 20257.529NONO
urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's stream
Dec 5, 20257.528NONO
The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in S
Apr 18, 20197.526NONO
An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catast
Jun 29, 20217.525NONO
The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy (if a
Mar 15, 20216.523NONO
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of put
Sep 30, 20206.523NONO

Exploit Exposure

Signals from CVEs in this product scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (19 CVEs).

Media Mentions

Signals from CVEs in this product scope (19 CVEs).

Top CNAs Publishing CVEs For Urllib3

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.1813.70.8%00
1.1713.70.8%00