Known vulnerabilities in python-urllib3 (Red Hat package)
Vendor:
Red Hat Inc.
Software:
python-urllib3 (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:python-urllib3_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
65
Public exploits:
6
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
1.24.2-10.el8_10
1.26.5-8.el9_8
1.26.5-3.el8ost.3
1.26.19-4.el10_2
1.10.2-3.el6_10.1
1.10.2-7.el7_9.1
2.6.3-0.1.el8pc
2.6.3-0.1.el9pc
1.24.2-5.el8_4.1
1.24.2-5.el8_8.3
1.24.2-5.el8_6.4
1.26.5-6.el9_6.1
1.26.19-2.el10_0.1
1.26.5-3.el9_2.3
1.26.5-5.el9_4.3
1.26.5-3.el9_0.2
2.6.3-1.el8ui
1.24.2-9.el8_10
1.26.5-6.el9_7.1
1.26.19-2.el10_1.1
2.3.0-1.el9pc
2.2.3-1.el8ui
1.25.10-7.el8ost
2.2.3-1.el8pc
2.2.3-1.el9pc
1.26.20-1.el9ap
1.26.5-3.el9_0.1
1.26.5-3.el9_2.2
1.24.2-5.el8_8.2
1.25.10-6.el8ost
1.26.18-2.el8pc
1.24.2-5.el8_8.1
1.24.2-5.el8_6.1
1.25.10-5.el8ost
1.26.18-0.1.el8pc
1.26.8-2.el8pc
1.26.18-1.el9ap
1.26.4-1.el8pc
1.26.7-1.el8pc
1.26.2-1.el7
1.26.5-1.el7pc
1.24.3-2.el7
1.24.2-5.el8
1.25.11-1.el7pc
1.24.3-1.el7
1.23-5.el8
1.24.2-2.el8
1.10.2-7.el7
1.21.1-1.2.el7ost
1.5-5.1.2.el6
1.8.2-4.1.el6
1.10.2-3.el7
1.21.1-1.el7
1.16-2.el7
1.16-1.el7
1.15.1-2.el7
1.10.4-8.el7
1.10.4-7.el7
1.8.2-5.el7
1.8.2-4.el7
1.10.2-1.el6
1.10.2-3.el6
1.5-5.el6
Vulnerabilities (65)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU130907 - Exposure of sensitive information to an unauthorized actor CVE-2026-44431 |
CWE-200 | Medium | 1.24.2-10.el8_10, 1.26.5-8.el9_8, 1.26.19-4.el10_2 | 09.05.2026 |
SB20260509126 SB2026051588 SB2026051589 and 36 more |
||
| #VU130906 - Improper Handling of Highly Compressed Data (Data Amplification) CVE-2026-44432 |
CWE-409 | Medium | 1.26.5-8.el9_8, 1.26.19-4.el10_2 | 09.05.2026 |
SB20260509126 SB2026052935 SB2026060609 and 12 more |
||
| #VU121072 - Improper Handling of Highly Compressed Data (Data Amplification) CVE-2026-21441 |
CWE-409 | Medium | 1.24.2-5.el8_4.1, 1.24.2-5.el8_6.4, 1.24.2-5.el8_8.3, 1.24.2-9.el8_10, 1.26.5-3.el8ost.3, 1.26.5-3.el9_0.2, 1.26.5-3.el9_2.3, 1.26.5-5.el9_4.3, 1.26.5-6.el9_6.1, 1.26.5-6.el9_7.1, 1.26.19-2.el10_0.1, 1.26.19-2.el10_1.1 | 07.01.2026 |
SB2026010780 SB2026011269 SB2026011328 and 89 more |
||
| #VU119231 - Resource exhaustion CVE-2025-66471 |
CWE-400 | Medium | 1.10.2-3.el6_10.1, 1.10.2-7.el7_9.1, 1.24.2-5.el8_4.1, 1.24.2-5.el8_6.4, 1.24.2-5.el8_8.3, 1.24.2-9.el8_10, 1.26.5-3.el8ost.3, 1.26.5-3.el9_0.2, 1.26.5-3.el9_2.3, 1.26.5-5.el9_4.3, 1.26.5-6.el9_6.1, 1.26.5-6.el9_7.1, 1.26.19-2.el10_0.1, 1.26.19-2.el10_1.1 | 05.12.2025 |
SB2025120581 SB2025121208 SB2026011313 and 88 more |
||
| #VU119230 - Allocation of Resources Without Limits or Throttling CVE-2025-66418 |
CWE-770 | Medium | 1.24.2-5.el8_4.1, 1.24.2-5.el8_6.4, 1.24.2-5.el8_8.3, 1.24.2-9.el8_10, 1.26.5-3.el8ost.3, 1.26.5-3.el9_0.2, 1.26.5-3.el9_2.3, 1.26.5-5.el9_4.3, 1.26.5-6.el9_6.1, 1.26.5-6.el9_7.1, 1.26.19-2.el10_0.1, 1.26.19-2.el10_1.1 | 05.12.2025 |
SB2025120581 SB2025121208 SB2025121938 and 93 more |
||
| #VU105796 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2025-27610 |
CWE-22 | Medium | 2.3.0-1.el9pc | 17.03.2025 |
SB2025031756 SB20250317118 SB20250317119 and 15 more |
||
| #VU105689 - Improper Control of Generation of Code ('Code Injection') CVE-2025-27407 |
CWE-94 | High | 2.3.0-1.el9pc | 13.03.2025 |
SB2025031315 SB2025031316 SB2025040330 and 3 more |
||
| #VU103000 - Improper input validation CVE-2024-56374 |
CWE-20 | Medium | 2.3.0-1.el9pc | 20.01.2025 |
SB2025012005 SB2025012029 SB2025012030 and 11 more |
||
| #VU101972 - Security Features CVE-2024-56326 |
CWE-254 | Low | 2.3.0-1.el9pc | 27.12.2024 |
SB2024122789 SB2024122790 SB2024122791 and 78 more |
||
| #VU97593 - Improper Authentication CVE-2024-7012 |
CWE-287 | High | 2.2.3-1.el8pc, 2.2.3-1.el9pc | 19.09.2024 |
SB2024092064 SB2024092065 SB2024092066 and 1 more |
||
| #VU95444 - Improper input validation CVE-2024-41991 |
CWE-20 | Medium | 2.2.3-1.el8ui | 07.08.2024 |
SB2024080728 SB2024080771 SB2024080772 and 12 more |
||
| #VU95443 - Improper input validation CVE-2024-41990 |
CWE-20 | Medium | 2.2.3-1.el8ui | 07.08.2024 |
SB2024080728 SB2024080771 SB2024080772 and 11 more |
||
| #VU95442 - Resource exhaustion CVE-2024-41989 |
CWE-400 | High | 2.2.3-1.el8ui | 07.08.2024 |
SB2024080722 SB2024080728 SB2024080771 and 14 more |
||
| #VU90156 - Security Features CVE-2024-35195 |
CWE-254 | Low | 2.2.3-1.el8ui | 31.05.2024 |
SB2024053174 SB2024053188 SB2024053192 and 117 more |
||
| #VU89677 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2024-34064 |
CWE-79 | Medium | 2.2.3-1.el8ui | 20.05.2024 |
SB2024052067 SB2024052081 SB2024052082 and 83 more |
||
| #VU89381 - Uncontrolled Recursion CVE-2024-4340 |
CWE-674 | Medium | 2.2.3-1.el8ui | 13.05.2024 |
SB2024051329 SB2024051330 SB2024051352 and 15 more |
||
| #VU89167 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2024-1135 |
CWE-444 | Medium | 2.2.3-1.el8ui | 06.05.2024 |
SB2024050631 SB2024050632 SB2024050633 and 40 more |
||
| #VU89159 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2024-30251 |
CWE-835 | Medium | 2.2.3-1.el8ui | 06.05.2024 |
SB2024050618 SB2024061929 SB2024072506 and 12 more |
||
| #VU88804 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2024-27306 |
CWE-79 | Medium | 2.2.3-1.el8ui | 18.04.2024 |
SB2024041813 SB2024042444 SB2024042445 and 12 more |
||
| #VU87129 - NULL Pointer Dereference CVE-2024-26130 |
CWE-476 | Medium | 2.2.3-1.el8ui | 05.03.2024 |
SB2024030534 SB2024030535 SB2024030546 and 41 more |
Showing elements 1 - 20 out of 65