← Scan another repo

github.com/python-poetry/poetry

@ 92b74dcfe348

Submitted 8/4/2026, 10:28:00 AM · Status: ok

Risk grade
F
100 / 100
Findings
268
0 critical53 high193 medium2 low20 info0 on CISA KEV0ATT&CK
Showing 268 of 268 findings

Findings

  • `Cookie` HTTP header isn't stripped on cross-origin redirects
    grypeCVE-2023-43804EPSS 1.2%
  • `Cookie` HTTP header isn't stripped on cross-origin redirects
    grypeCVE-2023-43804EPSS 1.2%
  • `Cookie` HTTP header isn't stripped on cross-origin redirects
    grypeCVE-2023-43804EPSS 1.2%
  • Catastrophic backtracking in URL authority parser when passed URL containing many @ characters
    grypeCVE-2021-33503EPSS 3.3%
  • Catastrophic backtracking in URL authority parser when passed URL containing many @ characters
    grypeCVE-2021-33503EPSS 3.3%
  • cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
    grypeCVE-2026-69247
  • Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
    grypeCVE-2026-21441EPSS 2.7%
  • Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
    grypeCVE-2026-21441EPSS 2.7%
  • Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
    grypeCVE-2026-21441EPSS 2.7%
  • Integer overflow in pywin32
    grypeCVE-2021-32559EPSS 1.7%
  • Removal of e-Tugra root certificate
    grypeCVE-2023-37920EPSS 0.6%
  • Removal of e-Tugra root certificate
    grypeCVE-2023-37920EPSS 0.6%
  • Removal of e-Tugra root certificate
    grypeCVE-2023-37920EPSS 0.6%
  • urllib3 allows an unbounded number of links in the decompression chain
    grypeCVE-2025-66418EPSS 0.7%
  • urllib3 allows an unbounded number of links in the decompression chain
    grypeCVE-2025-66418EPSS 0.7%
  • urllib3 allows an unbounded number of links in the decompression chain
    grypeCVE-2025-66418EPSS 0.7%
  • urllib3 streaming API improperly handles highly compressed data
    grypeCVE-2025-66471EPSS 0.7%
  • urllib3 streaming API improperly handles highly compressed data
    grypeCVE-2025-66471EPSS 0.7%
  • urllib3 streaming API improperly handles highly compressed data
    grypeCVE-2025-66471EPSS 0.7%
  • urllib3: Sensitive headers forwarded across origins in proxied low-level redirects
    grypeCVE-2026-44431EPSS 0.3%
  • urllib3: Sensitive headers forwarded across origins in proxied low-level redirects
    grypeCVE-2026-44431EPSS 0.3%
  • urllib3: Sensitive headers forwarded across origins in proxied low-level redirects
    grypeCVE-2026-44431EPSS 0.3%
  • cryptography is a package designed to expose cryptographic primitives ...
    cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, pkcs7_decrypt_pem, and pkcs7_decrypt_smime reported the outcome of decrypting a RecipientInfo's encryptedKey in several distinguish…
    trivyCVE-2026-69247
  • Integer overflow in pywin32
    An integer overflow exists in pywin32 prior to version b301 when adding an access control entry (ACE) to an access control list (ACL) that would cause the size to be greater than 65535 bytes. An attacker who successfully exploited this vulnerability could crash the vulnerable pro…
    trivyCVE-2021-32559
  • Integer overflow in pywin32
    An integer overflow exists in pywin32 prior to version b301 when adding an access control entry (ACE) to an access control list (ACL) that would cause the size to be greater than 65535 bytes. An attacker who successfully exploited this vulnerability could crash the vulnerable pro…
    trivyCVE-2021-32559
  • Integer overflow in pywin32
    An integer overflow exists in pywin32 prior to version b301 when adding an access control entry (ACE) to an access control list (ACL) that would cause the size to be greater than 65535 bytes. An attacker who successfully exploited this vulnerability could crash the vulnerable pro…
    trivyCVE-2021-32559
  • python-certifi: Removal of e-Tugra root certificate
    Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an invest…
    trivyCVE-2023-37920
  • python-certifi: Removal of e-Tugra root certificate
    Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an invest…
    trivyCVE-2023-37920
  • python-certifi: Removal of e-Tugra root certificate
    Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an invest…
    trivyCVE-2023-37920
  • python-certifi: Removal of e-Tugra root certificate
    Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an invest…
    trivyCVE-2023-37920
  • python-urllib3: Cookie request header isn't stripped during cross-origin redirects
    urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unk…
    trivyCVE-2023-43804
  • python-urllib3: Cookie request header isn't stripped during cross-origin redirects
    urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unk…
    trivyCVE-2023-43804
  • python-urllib3: Cookie request header isn't stripped during cross-origin redirects
    urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unk…
    trivyCVE-2023-43804
  • python-urllib3: Cookie request header isn't stripped during cross-origin redirects
    urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unk…
    trivyCVE-2023-43804
  • python-urllib3: ReDoS in the parsing of authority part of URL
    An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected t…
    trivyCVE-2021-33503
  • python-urllib3: ReDoS in the parsing of authority part of URL
    An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected t…
    trivyCVE-2021-33503
  • python-urllib3: ReDoS in the parsing of authority part of URL
    An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected t…
    trivyCVE-2021-33503
  • urllib3: urllib3 Streaming API improperly handles highly compressed data
    urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chu…
    trivyCVE-2025-66471
  • urllib3: urllib3 Streaming API improperly handles highly compressed data
    urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chu…
    trivyCVE-2025-66471
  • urllib3: urllib3 Streaming API improperly handles highly compressed data
    urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chu…
    trivyCVE-2025-66471
  • urllib3: urllib3 Streaming API improperly handles highly compressed data
    urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chu…
    trivyCVE-2025-66471
  • urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
    urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression b…
    trivyCVE-2026-21441
  • urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
    urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression b…
    trivyCVE-2026-21441
  • urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
    urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression b…
    trivyCVE-2026-21441
  • urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
    urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression b…
    trivyCVE-2026-21441
  • urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers
    urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.
    trivyCVE-2026-44431
  • urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers
    urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.
    trivyCVE-2026-44431
  • urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers
    urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.
    trivyCVE-2026-44431
  • urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers
    urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.
    trivyCVE-2026-44431
  • urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion
    urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage a…
    trivyCVE-2025-66418
  • urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion
    urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage a…
    trivyCVE-2025-66418
  • urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion
    urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage a…
    trivyCVE-2025-66418
  • urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion
    urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage a…
    trivyCVE-2025-66418

This report is public.