Urllib3

Latest version: v2.2.1

The latest version of urllib3 with no known security vulnerabilities is 2.2.1. We recommend installing version 2.2.1.

The information on this page was curated by experts in our Cybersecurity Intelligence Team.

Latest release
v2.2.1 at Feb. 18, 2024
License
MIT (MIT License)

Description

HTTP library with thread-safe connection pooling, file post, and more.

Resources

Vulnerabilities (11)

See all vulnerabilities
Affected versions:

<1.26.18 | >=2.0.0a1,<2.0.7

Urllib3 1.26.18 and 2.0.7 include a fix for CVE-2023-45803: Re…
Affected versions:

<1.26.17 | >=2.0.0a1,<2.0.5

Urllib3 1.26.17 and 2.0.5 include a fix for CVE-2023-43804: Ur…
Affected versions:

==1.17 | ==1.18

Urllib3 version 1.18.1 includes a fix for CVE-2016-9015: Versi…
Affected versions:

<1.26.5

Urllib3 1.26.5 includes a fix for CVE-2021-33503: When provide…
Affected versions:

>=1.26.0,<1.26.4

Urllib3 1.26.4 includes a fix for CVE-2021-28363: The urllib3 …
Affected versions:

<1.25.9

Urllib3 1.25.9 includes a fix for CVE-2020-26137: Urllib3 befo…

Versions (96)

See all versions

Has known vulnerabilities

  • 2.2.1
  • 2.2.0
  • 2.1.0
  • 2.0.7
  • 2.0.6
  • 2.0.5
  • 2.0.4
  • 2.0.3
  • 2.0.2
  • 2.0.1
  • 2.0.0
  • 2.0.0a4
  • 2.0.0a3
  • 2.0.0a2
  • 2.0.0a1
  • 1.26.18
  • 1.26.17
  • 1.26.16
  • 1.26.15
  • 1.26.14