Urllib3
Vendor:
First CVE: Jan 11, 2017 · Active for 9 years
19
Total CVEs
More Total CVEs than 93% of tracked products
2.1
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 35% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Urllib3 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 11, 2017
9 years ago
Most Recent CVE
May 13, 2026
74 days ago
CVE Severity & Scoring
Urllib319 CVEs
47%
42%
All CVEs352,719 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (94.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (5.3%)
Attack Complexity
Low17 (89.5%)
High2 (10.5%)
Unknown0 (0.0%)
User Interaction
None15 (78.9%)
Unknown0 (0.0%)
Required4 (21.1%)
Privileges Required
Low2 (10.5%)
High1 (5.3%)
None16 (84.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-44432HIGH urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPRes | May 13, 2026 | 7.5 | 38 | NO | NO |
CVE-2026-21441HIGH urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than l | Jan 7, 2026 | 7.5 | 33 | NO | NO |
CVE-2018-20060CRITICAL urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can | Dec 11, 2018 | 9.8 | 33 | NO | NO |
CVE-2026-44431MEDIUM urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., | May 13, 2026 | 5.3 | 31 | NO | NO |
CVE-2025-66418HIGH urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a mali | Dec 5, 2025 | 7.5 | 29 | NO | NO |
CVE-2025-66471HIGH urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's stream | Dec 5, 2025 | 7.5 | 28 | NO | NO |
CVE-2019-11324HIGH The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS store of CA certificates, which results in S | Apr 18, 2019 | 7.5 | 26 | NO | NO |
CVE-2021-33503HIGH An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catast | Jun 29, 2021 | 7.5 | 25 | NO | NO |
CVE-2021-28363MEDIUM The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy (if a | Mar 15, 2021 | 6.5 | 23 | NO | NO |
CVE-2020-26137MEDIUM urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of put | Sep 30, 2020 | 6.5 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (19 CVEs).
Media Mentions
Signals from CVEs in this product scope (19 CVEs).
Top CNAs Publishing CVEs For Urllib3
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.18 | 1 | 3.7 | 0.8% | 0 | 0 |
| 1.17 | 1 | 3.7 | 0.8% | 0 | 0 |