{"schema_version":1,"title":"urllib3 (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 22 vulnerabilities in urllib3 (PyPI): 0 in the last 7 days and 3 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2025-50182, was published on 7 July 2026.","url":"https://junglewise.ai/threats/technologies/urllib3","json_url":"https://junglewise.ai/threats/technologies/urllib3.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/urllib3","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":6,"all_time":22,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":3,"last_365_days":9},"latest":[{"cve":"CVE-2025-50182","cvss":3.1,"epss":0.0039,"slug":"cve-2025-50182-urllib3-does-not-control-redirects-in-browsers-and-node-js","title":"PYSEC-2026-1997 - urllib3 does not control redirects in browsers and Node.js","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:55.593591+00:00","url":"https://junglewise.ai/threats/cve-2025-50182-urllib3-does-not-control-redirects-in-browsers-and-node-js"},{"cve":"CVE-2025-50181","cvss":3.1,"epss":0.0047,"slug":"cve-2025-50181-urllib3-redirects-are-not-disabled-when-retries-are-disabled-on","title":"PYSEC-2026-1999 - urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:55.519678+00:00","url":"https://junglewise.ai/threats/cve-2025-50181-urllib3-redirects-are-not-disabled-when-retries-are-disabled-on"},{"cve":"CVE-2024-37891","cvss":3.1,"epss":0.0114,"slug":"cve-2024-37891-urllib3-proxy-authorization-header-leak-in-cross-origin-redirects","title":"PYSEC-2026-1995 - urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:34.848392+00:00","url":"https://junglewise.ai/threats/cve-2024-37891-urllib3-proxy-authorization-header-leak-in-cross-origin-redirects"},{"cve":"CVE-2026-9375","cvss":7.5,"slug":"cve-2026-9375-urllib3-denial-of-service-via-brotli-decompression-bomb-bypass","title":"urllib3 denial of service via Brotli decompression bomb bypass","severity":"high","exploited":false,"published_at":"2026-06-19T19:16:36.947+00:00","url":"https://junglewise.ai/threats/cve-2026-9375-urllib3-denial-of-service-via-brotli-decompression-bomb-bypass"},{"cve":"CVE-2026-44432","cvss":7.5,"epss":0.0088,"slug":"cve-2026-44432-urllib3-resource-exhaustion-via-improper-handling-of-compressed","title":"urllib3 resource exhaustion via improper handling of compressed data","severity":"high","exploited":false,"published_at":"2026-05-13T16:16:57.303+00:00","url":"https://junglewise.ai/threats/cve-2026-44432-urllib3-resource-exhaustion-via-improper-handling-of-compressed"},{"cve":"CVE-2026-44431","cvss":5.3,"epss":0.0034,"slug":"cve-2026-44431-urllib3-sensitive-header-leak-in-proxymanager-low-level-redirects","title":"urllib3 sensitive header leak in ProxyManager low-level redirects","severity":"medium","exploited":false,"published_at":"2026-05-13T16:16:57.15+00:00","url":"https://junglewise.ai/threats/cve-2026-44431-urllib3-sensitive-header-leak-in-proxymanager-low-level-redirects"},{"cve":"CVE-2026-21441","cvss":7.5,"epss":0.0297,"slug":"cve-2026-21441-python-urllib3-denial-of-service-via-decompression-bomb-in","title":"Python urllib3 denial of service via decompression bomb in redirects","severity":"high","exploited":false,"published_at":"2026-01-07T22:15:44.04+00:00","url":"https://junglewise.ai/threats/cve-2026-21441-python-urllib3-denial-of-service-via-decompression-bomb-in"},{"cve":"CVE-2025-66471","cvss":7.5,"epss":0.0068,"slug":"cve-2025-66471-urllib3-streaming-api-improper-compression-handling","title":"urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles","severity":"high","exploited":false,"published_at":"2025-12-05T17:16:04.4+00:00","url":"https://junglewise.ai/threats/cve-2025-66471-urllib3-streaming-api-improper-compression-handling"},{"cve":"CVE-2025-66418","cvss":7.5,"epss":0.0068,"slug":"cve-2025-66418-urllib3-is-a-user-friendly-http-client-library-for-python","title":"urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompres","severity":"high","exploited":false,"published_at":"2025-12-05T16:15:51.053+00:00","url":"https://junglewise.ai/threats/cve-2025-66418-urllib3-is-a-user-friendly-http-client-library-for-python"},{"cve":"CVE-2023-45803","cvss":3.1,"epss":0.0054,"slug":"cve-2023-45803-urllib3-s-request-body-not-stripped-after-redirect-from-303","title":"PYSEC-2023-212 - urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP request body when an HTTP redirect re","severity":"low","exploited":false,"published_at":"2023-10-17T20:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-45803-urllib3-s-request-body-not-stripped-after-redirect-from-303"},{"cve":"CVE-2018-25091","cvss":3.1,"epss":0.0052,"slug":"cve-2018-25091-authorization-header-forwarded-on-redirect","title":"PYSEC-2023-207 - urllib3 before 1.24.2 does not remove the authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in","severity":"low","exploited":false,"published_at":"2023-10-15T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2018-25091-authorization-header-forwarded-on-redirect"},{"cve":"CVE-2023-43804","cvss":3.1,"epss":0.0121,"slug":"cve-2023-43804-cookie-http-header-isn-t-stripped-on-cross-origin-redirects","title":"PYSEC-2023-192 - urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for","severity":"low","exploited":false,"published_at":"2023-10-04T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-43804-cookie-http-header-isn-t-stripped-on-cross-origin-redirects"},{"cve":"CVE-2021-33503","cvss":7.5,"epss":0.0327,"slug":"cve-2021-33503-urllib3-redos-in-url-authority-parser","title":"urllib3 ReDoS in URL authority parser","severity":"high","exploited":false,"published_at":"2021-06-01T21:19:32+00:00","url":"https://junglewise.ai/threats/cve-2021-33503-urllib3-redos-in-url-authority-parser"},{"cve":"CVE-2021-28363","cvss":3.1,"epss":0.0211,"slug":"cve-2021-28363-using-default-sslcontext-for-https-requests-in-an-https-proxy","title":"PYSEC-2021-59 - The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The ini","severity":"low","exploited":false,"published_at":"2021-03-15T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-28363-using-default-sslcontext-for-https-requests-in-an-https-proxy"},{"cve":"CVE-2020-26137","cvss":3.1,"epss":0.0227,"slug":"cve-2020-26137-crlf-injection-in-urllib3","title":"PYSEC-2020-148 - urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control","severity":"low","exploited":false,"published_at":"2020-09-30T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-26137-crlf-injection-in-urllib3"},{"cve":"CVE-2020-7212","cvss":3.1,"epss":0.0337,"slug":"cve-2020-7212-uncontrolled-resource-consumption-in-urllib3","title":"PYSEC-2020-149 - The _encode_invalid_chars function in util/url.py in the urllib3 library 1.25.2 through 1.25.7 for Python allows a denial of service (CPU co","severity":"low","exploited":false,"published_at":"2020-03-06T20:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-7212-uncontrolled-resource-consumption-in-urllib3"},{"slug":"pysec-2019-63-the-urllib3-library-before-1-24-2-for-python-mishandles-2035a86a","title":"PYSEC-2019-63 - The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS stor","severity":"info","exploited":false,"published_at":"2019-04-18T21:29:00+00:00","url":"https://junglewise.ai/threats/pysec-2019-63-the-urllib3-library-before-1-24-2-for-python-mishandles-2035a86a"},{"cve":"CVE-2019-11324","cvss":3,"epss":0.0284,"slug":"cve-2019-11324-improper-certificate-validation-in-urllib3","title":"PYSEC-2019-133 - The urllib3 library before 1.24.2 for Python mishandles certain cases where the desired set of CA certificates is different from the OS stor","severity":"low","exploited":false,"published_at":"2019-04-18T21:29:00+00:00","url":"https://junglewise.ai/threats/cve-2019-11324-improper-certificate-validation-in-urllib3"},{"cve":"CVE-2019-11236","cvss":3,"epss":0.0207,"slug":"cve-2019-11236-improper-neutralization-of-crlf-sequences-in-urllib3-library-for","title":"PYSEC-2019-132 - In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.","severity":"low","exploited":false,"published_at":"2019-04-15T15:29:00+00:00","url":"https://junglewise.ai/threats/cve-2019-11236-improper-neutralization-of-crlf-sequences-in-urllib3-library-for"},{"slug":"pysec-2019-62-in-the-urllib3-library-through-1-24-1-for-python-crlf-2b64885a","title":"PYSEC-2019-62 - In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.","severity":"info","exploited":false,"published_at":"2019-04-15T15:29:00+00:00","url":"https://junglewise.ai/threats/pysec-2019-62-in-the-urllib3-library-through-1-24-1-for-python-crlf-2b64885a"},{"cve":"CVE-2018-20060","cvss":3,"epss":0.0449,"slug":"cve-2018-20060-exposure-of-sensitive-information-to-an-unauthorized-actor-in","title":"PYSEC-2018-32 - urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that diff","severity":"low","exploited":false,"published_at":"2018-12-11T17:29:00+00:00","url":"https://junglewise.ai/threats/cve-2018-20060-exposure-of-sensitive-information-to-an-unauthorized-actor-in"},{"cve":"CVE-2016-9015","cvss":3,"epss":0.0075,"slug":"cve-2016-9015-urllib3-incorrect-certificate-validation","title":"PYSEC-2017-98 - Versions 1.17 and 1.18 of the Python urllib3 library suffer from a vulnerability that can cause them, in certain configurations, to not corr","severity":"low","exploited":false,"published_at":"2017-01-11T16:59:00+00:00","url":"https://junglewise.ai/threats/cve-2016-9015-urllib3-incorrect-certificate-validation"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"picklescan (PyPI)","slug":"picklescan","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/picklescan"},{"name":"openbabel (PyPI)","slug":"openbabel","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/openbabel"},{"name":"apache-superset (PyPI)","slug":"apache-superset","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/apache-superset"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"weblate (PyPI)","slug":"weblate","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/weblate"},{"name":"mcp-atlassian (PyPI)","slug":"mcp-atlassian","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/mcp-atlassian"},{"name":"crawl4ai (PyPI)","slug":"crawl4ai","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/crawl4ai"},{"name":"moin (PyPI)","slug":"moin","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/moin"}],"technology":{"hub":true,"name":"urllib3 (PyPI)","slug":"urllib3","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://urllib3.readthedocs.io/","repo_url":"https://github.com/urllib3/urllib3","description":"A HTTP client library for Python featuring thread-safe connection pooling and file upload support.","url":"https://junglewise.ai/threats/technologies/urllib3"},"most_severe":[{"cve":"CVE-2021-33503","cvss":7.5,"epss":0.0327,"slug":"cve-2021-33503-urllib3-redos-in-url-authority-parser","title":"urllib3 ReDoS in URL authority parser","severity":"high","exploited":false,"published_at":"2021-06-01T21:19:32+00:00","url":"https://junglewise.ai/threats/cve-2021-33503-urllib3-redos-in-url-authority-parser"},{"cve":"CVE-2026-21441","cvss":7.5,"epss":0.0297,"slug":"cve-2026-21441-python-urllib3-denial-of-service-via-decompression-bomb-in","title":"Python urllib3 denial of service via decompression bomb in redirects","severity":"high","exploited":false,"published_at":"2026-01-07T22:15:44.04+00:00","url":"https://junglewise.ai/threats/cve-2026-21441-python-urllib3-denial-of-service-via-decompression-bomb-in"},{"cve":"CVE-2026-44432","cvss":7.5,"epss":0.0088,"slug":"cve-2026-44432-urllib3-resource-exhaustion-via-improper-handling-of-compressed","title":"urllib3 resource exhaustion via improper handling of compressed data","severity":"high","exploited":false,"published_at":"2026-05-13T16:16:57.303+00:00","url":"https://junglewise.ai/threats/cve-2026-44432-urllib3-resource-exhaustion-via-improper-handling-of-compressed"},{"cve":"CVE-2025-66471","cvss":7.5,"epss":0.0068,"slug":"cve-2025-66471-urllib3-streaming-api-improper-compression-handling","title":"urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles","severity":"high","exploited":false,"published_at":"2025-12-05T17:16:04.4+00:00","url":"https://junglewise.ai/threats/cve-2025-66471-urllib3-streaming-api-improper-compression-handling"},{"cve":"CVE-2025-66418","cvss":7.5,"epss":0.0068,"slug":"cve-2025-66418-urllib3-is-a-user-friendly-http-client-library-for-python","title":"urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompres","severity":"high","exploited":false,"published_at":"2025-12-05T16:15:51.053+00:00","url":"https://junglewise.ai/threats/cve-2025-66418-urllib3-is-a-user-friendly-http-client-library-for-python"},{"cve":"CVE-2026-9375","cvss":7.5,"slug":"cve-2026-9375-urllib3-denial-of-service-via-brotli-decompression-bomb-bypass","title":"urllib3 denial of service via Brotli decompression bomb bypass","severity":"high","exploited":false,"published_at":"2026-06-19T19:16:36.947+00:00","url":"https://junglewise.ai/threats/cve-2026-9375-urllib3-denial-of-service-via-brotli-decompression-bomb-bypass"},{"cve":"CVE-2026-44431","cvss":5.3,"epss":0.0034,"slug":"cve-2026-44431-urllib3-sensitive-header-leak-in-proxymanager-low-level-redirects","title":"urllib3 sensitive header leak in ProxyManager low-level redirects","severity":"medium","exploited":false,"published_at":"2026-05-13T16:16:57.15+00:00","url":"https://junglewise.ai/threats/cve-2026-44431-urllib3-sensitive-header-leak-in-proxymanager-low-level-redirects"},{"cve":"CVE-2020-7212","cvss":3.1,"epss":0.0337,"slug":"cve-2020-7212-uncontrolled-resource-consumption-in-urllib3","title":"PYSEC-2020-149 - The _encode_invalid_chars function in util/url.py in the urllib3 library 1.25.2 through 1.25.7 for Python allows a denial of service (CPU co","severity":"low","exploited":false,"published_at":"2020-03-06T20:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-7212-uncontrolled-resource-consumption-in-urllib3"},{"cve":"CVE-2020-26137","cvss":3.1,"epss":0.0227,"slug":"cve-2020-26137-crlf-injection-in-urllib3","title":"PYSEC-2020-148 - urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control","severity":"low","exploited":false,"published_at":"2020-09-30T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-26137-crlf-injection-in-urllib3"},{"cve":"CVE-2021-28363","cvss":3.1,"epss":0.0211,"slug":"cve-2021-28363-using-default-sslcontext-for-https-requests-in-an-https-proxy","title":"PYSEC-2021-59 - The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The ini","severity":"low","exploited":false,"published_at":"2021-03-15T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-28363-using-default-sslcontext-for-https-requests-in-an-https-proxy"}],"generated_at":"2026-09-26T13:07:00.120236+00:00"}