2.6.3
16 years ago
17 days ago
Known vulnerabilities in the urllib3 package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
urllib3 is a HTTP library with thread-safe connection pooling, file post, and more. Affected versions of this package are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) via the streaming API when handling HTTP redirects. An attacker can cause excessive resource consumption by serving a specially crafted compressed response that triggers decompression of large amounts of data before any read limits are enforced. Note: This is only exploitable if content is streamed from untrusted sources with redirects enabled. How to fix Improper Handling of Highly Compressed Data (Data Amplification)? Upgrade | [1.22,2.6.3) |