Technology · PyPI
urllib3 (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 22 vulnerabilities in urllib3 (PyPI): 0 in the last 7 days and 3 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2025-50182, was published on 7 July 2026.
- Last 7 days
- 0
- Last 90 days
- 3
- Critical, all time
- 0
- Exploited in the wild
- 0
About urllib3 (PyPI)
A HTTP client library for Python featuring thread-safe connection pooling and file upload support.
Latest urllib3 (PyPI) vulnerabilities
- CVE-2025-50182: PYSEC-2026-1997 - urllib3 does not control redirects in browsers and Node.jslowCVSS 3.1EPSS 0.4%
- CVE-2025-50181: PYSEC-2026-1999 - urllib3 redirects are not disabled when retries are disabled on PoolManager instantiationlowCVSS 3.1EPSS 0.5%
- CVE-2024-37891: PYSEC-2026-1995 - urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirectslowCVSS 3.1EPSS 1.1%
- CVE-2026-9375: urllib3 denial of service via Brotli decompression bomb bypasshighCVSS 7.5
- CVE-2026-44432: urllib3 resource exhaustion via improper handling of compressed datahighCVSS 7.5EPSS 0.9%
- CVE-2026-44431: urllib3 sensitive header leak in ProxyManager low-level redirectsmediumCVSS 5.3EPSS 0.3%
- CVE-2026-21441: Python urllib3 denial of service via decompression bomb in redirectshighCVSS 7.5EPSS 3.0%
- CVE-2025-66471: urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API…highCVSS 7.5EPSS 0.7%
- CVE-2025-66418: urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of…highCVSS 7.5EPSS 0.7%
- CVE-2023-45803: PYSEC-2023-212 - urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP…lowCVSS 3.1EPSS 0.5%
- CVE-2018-25091: PYSEC-2023-207 - urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin…lowCVSS 3.1EPSS 0.5%
- CVE-2023-43804: PYSEC-2023-192 - urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header…lowCVSS 3.1EPSS 1.2%
- CVE-2021-33503: urllib3 ReDoS in URL authority parserhighCVSS 7.5EPSS 3.3%
- CVE-2021-28363: PYSEC-2021-59 - The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases…lowCVSS 3.1EPSS 2.1%
- CVE-2020-26137: PYSEC-2020-148 - urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as…lowCVSS 3.1EPSS 2.3%
- CVE-2020-7212: PYSEC-2020-149 - The _encode_invalid_chars function in util/url.py in the urllib3 library 1.25.2 through 1.25.7 for Python…lowCVSS 3.1EPSS 3.4%
- PYSEC-2019-63 - The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is…info
- CVE-2019-11324: PYSEC-2019-133 - The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA…lowCVSS 3EPSS 2.8%
- CVE-2019-11236: PYSEC-2019-132 - In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the…lowCVSS 3EPSS 2.1%
- PYSEC-2019-62 - In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.info
- CVE-2018-20060: PYSEC-2018-32 - urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin…lowCVSS 3EPSS 4.5%
- CVE-2016-9015: PYSEC-2017-98 - Versions 1.17 and 1.18 of the Python urllib3 library suffer from a vulnerability that can cause them, in…lowCVSS 3EPSS 0.8%
Most severe urllib3 (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2021-33503: urllib3 ReDoS in URL authority parserhighCVSS 7.5EPSS 3.3%
- CVE-2026-21441: Python urllib3 denial of service via decompression bomb in redirectshighCVSS 7.5EPSS 3.0%
- CVE-2026-44432: urllib3 resource exhaustion via improper handling of compressed datahighCVSS 7.5EPSS 0.9%
- CVE-2025-66471: urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API…highCVSS 7.5EPSS 0.7%
- CVE-2025-66418: urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of…highCVSS 7.5EPSS 0.7%
- CVE-2026-9375: urllib3 denial of service via Brotli decompression bomb bypasshighCVSS 7.5
- CVE-2026-44431: urllib3 sensitive header leak in ProxyManager low-level redirectsmediumCVSS 5.3EPSS 0.3%
- CVE-2020-7212: PYSEC-2020-149 - The _encode_invalid_chars function in util/url.py in the urllib3 library 1.25.2 through 1.25.7 for Python…lowCVSS 3.1EPSS 3.4%
- CVE-2020-26137: PYSEC-2020-148 - urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as…lowCVSS 3.1EPSS 2.3%
- CVE-2021-28363: PYSEC-2021-59 - The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases…lowCVSS 3.1EPSS 2.1%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 3 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/urllib3.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "urllib3 (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/urllib3, 26 September 2026.