Search CVE reports


Toggle filters

1 – 10 of 24 results


CVE-2026-97689

Medium priority
Needs evaluation

urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk parser buffers the chunk-size field...

2 affected packages

python-urllib3, python-pip

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-urllib3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
python-pip Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-97688

Medium priority
Needs evaluation

urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the Deflate decoder retains trailing bytes as unconsumed input after...

2 affected packages

python-urllib3, python-pip

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-urllib3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
python-pip Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-97687

Medium priority
Needs evaluation

urllib3 is an HTTP client library for Python. From 1.26.0 until 2.8.0, the proxy_ssl_context, proxy_assert_hostname, proxy_assert_fingerprint, ssl_context, cert_reqs, verify_mode, use_forwarding_for_https=True, and CERT_NONE...

2 affected packages

python-urllib3, python-pip

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-urllib3 Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
python-pip Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-9375

Medium priority
Vulnerable

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

2 affected packages

python-urllib3, python-pip

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-urllib3 Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
python-pip Vulnerable Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2026-44432

Medium priority

Some fixes available 1 of 9

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was...

2 affected packages

python-pip, python-urllib3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-pip Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
python-urllib3 Fixed Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-44431

Medium priority

Some fixes available 7 of 16

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these...

2 affected packages

python-urllib3, python-pip

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-urllib3 Fixed Fixed Fixed Fixed Fixed
python-pip Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-21441

Medium priority

Some fixes available 6 of 13

urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at...

2 affected packages

python-pip, python-urllib3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-pip Vulnerable Vulnerable Vulnerable Fixed Ignored
python-urllib3 Not affected Fixed Fixed Fixed Ignored
Show less packages

CVE-2025-66471

Medium priority

Some fixes available 7 of 18

urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of...

2 affected packages

python-pip, python-urllib3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-pip Fixed Fixed Fixed Ignored Ignored
python-urllib3 Fixed Fixed Ignored Ignored Ignored
Show less packages

CVE-2025-66418

Medium priority

Some fixes available 10 of 12

urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited...

2 affected packages

python-pip, python-urllib3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-pip Fixed Fixed Fixed Fixed Not affected
python-urllib3 Fixed Fixed Fixed Fixed Not affected
Show less packages

CVE-2025-50182

Medium priority
Fixed

urllib3 is a user-friendly HTTP client library for Python. Starting in version 2.2.0 and prior to 2.5.0, urllib3 does not control redirects in browsers and Node.js. urllib3 supports being used in a Pyodide runtime utilizing the...

2 affected packages

python-pip, python-urllib3

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-pip — Not affected Not affected Not affected Not affected
python-urllib3 — Not affected Not affected Not affected Not affected
Show less packages