Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 32

Количество 32

rocky логотип

RLSA-2026:32992

около 1 месяца назад

Important: python3.12-urllib3 security update

EPSS: Низкий
rocky логотип

RLSA-2026:28159

около 1 месяца назад

Important: python3.12-urllib3 security update

EPSS: Низкий
rocky логотип

RLSA-2026:28158

около 1 месяца назад

Important: python-urllib3 security update

EPSS: Низкий
rocky логотип

RLSA-2026:28157

около 1 месяца назад

Important: python3.14-urllib3 security update

EPSS: Низкий
rocky логотип

RLSA-2026:28000

около 1 месяца назад

Important: python-urllib3 security update

EPSS: Низкий
rocky логотип

RLSA-2026:27929

около 1 месяца назад

Important: python3.14-urllib3 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-32992

около 1 месяца назад

ELSA-2026-32992: python3.12-urllib3 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-28159

около 1 месяца назад

ELSA-2026-28159: python3.12-urllib3 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-28158

около 1 месяца назад

ELSA-2026-28158: python-urllib3 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-28157

около 1 месяца назад

ELSA-2026-28157: python3.14-urllib3 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-28000

16 дней назад

ELSA-2026-28000: python-urllib3 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-27929

16 дней назад

ELSA-2026-27929: python3.14-urllib3 security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2026-44432

3 месяца назад

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-44432

3 месяца назад

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-44432

3 месяца назад

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-44432

3 месяца назад

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7 ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-44431

3 месяца назад

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2026-44431

3 месяца назад

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2026-44431

3 месяца назад

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2026-44431

3 месяца назад

urllib3: Sensitive headers forwarded across origins in proxied low-level redirects

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2026:32992

Important: python3.12-urllib3 security update

около 1 месяца назад
rocky логотип
RLSA-2026:28159

Important: python3.12-urllib3 security update

около 1 месяца назад
rocky логотип
RLSA-2026:28158

Important: python-urllib3 security update

около 1 месяца назад
rocky логотип
RLSA-2026:28157

Important: python3.14-urllib3 security update

около 1 месяца назад
rocky логотип
RLSA-2026:28000

Important: python-urllib3 security update

около 1 месяца назад
rocky логотип
RLSA-2026:27929

Important: python3.14-urllib3 security update

около 1 месяца назад
oracle-oval логотип
ELSA-2026-32992

ELSA-2026-32992: python3.12-urllib3 security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-28159

ELSA-2026-28159: python3.12-urllib3 security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-28158

ELSA-2026-28158: python-urllib3 security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-28157

ELSA-2026-28157: python3.14-urllib3 security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-28000

ELSA-2026-28000: python-urllib3 security update (IMPORTANT)

16 дней назад
oracle-oval логотип
ELSA-2026-27929

ELSA-2026-27929: python3.14-urllib3 security update (IMPORTANT)

16 дней назад
ubuntu логотип
CVE-2026-44432

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0.

CVSS3: 7.5
1%
Низкий
3 месяца назад
redhat логотип
CVE-2026-44432

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0.

CVSS3: 7.5
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-44432

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0.

CVSS3: 7.5
1%
Низкий
3 месяца назад
debian логотип
CVE-2026-44432

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7 ...

CVSS3: 7.5
1%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-44431

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.

CVSS3: 5.3
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-44431

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.

CVSS3: 5.9
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-44431

urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.

CVSS3: 5.3
0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-44431

urllib3: Sensitive headers forwarded across origins in proxied low-level redirects

0%
Низкий
3 месяца назад

Уязвимостей на страницу