Illia Volochii
12 exploits
Active since Oct 2023
Decompression Bomb Bypass via Negative max_length in Streaming API in urllib3
CVSS 7.5
HTTP client proxy tunnel headers not validated for CR/LF
HTTP client proxy tunnel headers not validated for CR/LF
HTTP client proxy tunnel headers not validated for CR/LF
HTTP client proxy tunnel headers not validated for CR/LF
urllib3 <1.26.17, <2.0.5 - Info Disclosure
CVSS 5.9
urllib3 < 1.26.18 and 2.0.0-2.0.7 - Exposure of Sensitive Information via HTTP Redirect
CVSS 4.2
urllib3 < 2.5.0 - Open Redirect via PoolManager Retry Configuration
CVSS 5.3
urllib3 2.2.0-2.5.0 - Open Redirect via Pyodide Runtime
CVSS 5.3
urllib3 1.24-2.5.x - Denial of Service via Unbounded Decompression Chain
CVSS 7.5
urllib3 1.0-2.5.9 - Denial of Service via Highly Compressed Data Handling
CVSS 7.5
urllib3 1.22-2.6.2 - Denial of Service via HTTP Redirect Response Decompression
CVSS 7.5