Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7 advisories

Loading
urllib3 does not control redirects in browsers and Node.js Moderate
CVE-2025-50182 was published for urllib3 (pip) Jun 18, 2025
illia-v Credited to illia-v, pquentin, and sethmlarson pquentin pquentin
sethmlarson sethmlarson
urllib3 redirects are not disabled when retries are disabled on PoolManager instantiation Moderate
CVE-2025-50181 was published for urllib3 (pip) Jun 18, 2025
sandumjacob Credited to sandumjacob, illia-v, pquentin, and sethmlarson illia-v illia-v
pquentin pquentin sethmlarson sethmlarson
Requests vulnerable to .netrc credentials leak via malicious URLs Moderate
CVE-2024-47081 was published for requests (pip) Jun 9, 2025
sethmlarson Credited to sethmlarson, jupenur, nateprewitt, and sigmavirus24 jupenur jupenur
nateprewitt nateprewitt sigmavirus24 sigmavirus24
check-jsonschema default caching for remote schemas allows for cache confusion Moderate
CVE-2024-53848 was published for check-jsonschema (pip) Dec 2, 2024
sethmlarson Credited to sethmlarson and sirosen sirosen sirosen
urllib3's request body not stripped after redirect from 303 status changes request method to GET Moderate
CVE-2023-45803 was published for urllib3 (pip) Oct 17, 2023
ranjit-git Credited to ranjit-git, illia-v, sethmlarson, and Hacked36 illia-v illia-v
sethmlarson sethmlarson Hacked36 Hacked36
aiohttp.web.Application vulnerable to HTTP request smuggling via llhttp HTTP request parser Moderate
CVE-2023-37276 was published for aiohttp (pip) Jul 20, 2023
sethmlarson Credited to sethmlarson and Dreamsorcerer Dreamsorcerer Dreamsorcerer
Unintended leak of Proxy-Authorization header in requests Moderate
CVE-2023-32681 was published for requests (pip) May 22, 2023
SmashITs Credited to SmashITs, tobiasfunke1, sethmlarson, and nateprewitt tobiasfunke1 tobiasfunke1
sethmlarson sethmlarson nateprewitt nateprewitt
ProTip! Advisories are also available from the GraphQL API