© 2025-2026 PySpect
First version without a known vulnerability: 2.7.0
urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API
Fixed in: 2.7.0
urllib3: Sensitive headers forwarded across origins in proxied low-level redirects
Fixed in: 2.7.0
Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
Fixed in: 2.6.3
urllib3 streaming API improperly handles highly compressed data
Fixed in: 2.6.0
urllib3 allows an unbounded number of links in the decompression chain
Fixed in: 2.6.0
urllib3 does not control redirects in browsers and Node.js
Fixed in: 2.5.0
urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation
Fixed in: 2.5.0
urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects
Fixed in: 1.26.19, 2.2.2
urllib3's request body not stripped after redirect from 303 status changes request method to GET
Fixed in: 2.0.7, 1.26.18, 4e98d57809dacab1cbe625fddeec1a290c478ea9
Authorization Header forwarded on redirect
Fixed in: 1.24.2, adb358f8e06865406d1f05e581a16cbea2136fbc
`Cookie` HTTP header isn't stripped on cross-origin redirects
Fixed in: 2.0.6, 1.26.17, 644124ecd0b6e417c527191f866daa05a5a2056d, 01220354d389cd05474713f8c982d05c9b17aafb
Urllib3 Incorrect Certificate Validation
Fixed in: 1.18.1
Improper Neutralization of CRLF Sequences in urllib3 library for Python
Fixed in: 1.24.3
CRLF injection in urllib3
Fixed in: 1.25.9, 1dd69c5c5982fae7c87a620d487c2ebf7a6b436b
Catastrophic backtracking in URL authority parser when passed URL containing many @ characters
Fixed in: 1.26.5, 2d4a3fee6de2fa45eb82169361918f759269b4ec
Uncontrolled Resource Consumption in urllib3
Fixed in: 1.25.8, a74c9cfbaed9f811e7563cfc3dce894928e0221a
Using default SSLContext for HTTPS requests in an HTTPS proxy doesn't verify certificate hostname for proxy connection
Fixed in: 1.26.4, 8d65ea1ecf6e2cdc27d42124e587c1b83a3118b0
Improper Certificate Validation in urllib3
Fixed in: 1.24.2
Exposure of Sensitive Information to an Unauthorized Actor in urllib3
Fixed in: 1.23