The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade urllib3
to version 2.5.0 or higher.
urllib3 is a HTTP library with thread-safe connection pooling, file post, and more.
Affected versions of this package are vulnerable to Open Redirect when used within a Pyodide runtime utilizing the JavaScript Fetch API or falling back on XMLHttpRequest
, due to the retries
and redirect
parameters being ignored and the runtime determining redirect behavior. An attacker can access sensitive information by leveraging uncontrolled redirects in browsers or Node.js environments.
Notes:
This is only exploitable if the application relies on the retries
and redirect
parameters to limit or prevent redirects;
This issue was fixed in version 2.5.0 for Node.js environments but not for browsers due to XMLHttpRequest
providing no control over redirects. Default browser behavior for redirects should be expected.