2.6.2
16 years ago
23 days ago
Known vulnerabilities in the urllib3 package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
urllib3 is a HTTP library with thread-safe connection pooling, file post, and more. Affected versions of this package are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) in the Streaming API. The Note: It is recommended to patch Brotli dependencies (upgrade to at least 1.2.0) if they are installed outside of How to fix Improper Handling of Highly Compressed Data (Data Amplification)? Upgrade | [1.0,2.6.0) |
urllib3 is a HTTP library with thread-safe connection pooling, file post, and more. Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling during the decompression of compressed response data. An attacker can cause excessive CPU and memory consumption by sending responses with a large number of chained compression steps. How to fix Allocation of Resources Without Limits or Throttling? Upgrade | [1.24,2.6.0) |
urllib3 is a HTTP library with thread-safe connection pooling, file post, and more. Affected versions of this package are vulnerable to Open Redirect due to the Note:
How to fix Open Redirect? Upgrade | [,2.5.0) |
urllib3 is a HTTP library with thread-safe connection pooling, file post, and more. Affected versions of this package are vulnerable to Improper Removal of Sensitive Information Before Storage or Transfer due to the improper handling of the Notes: To be vulnerable, the application must be doing all of the following:
How to fix Improper Removal of Sensitive Information Before Storage or Transfer? Upgrade | [,1.26.19)[2.0.0a1,2.2.2) |