gitsafehub
github.com/untitaker/urllib3 ↗

untitaker/urllib3

scanned 2026-08-11 · git a277586
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 5 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secrets29Vulnerable dependenciesKnown OSS vulnerabilities59Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks 29 found · 29 serious

API keys, passwords or tokens committed into the repo.

  • Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    dummyserver/certs/cacert.no_san.pem:14
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    dummyserver/certs/cacert.key:1
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    dummyserver/certs/client.key:1
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    dummyserver/certs/server.key.org:1
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    dummyserver/certs/server.key:1
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    dummyserver/certs/cacert.key:1
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    dummyserver/certs/client.key:1
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    dummyserver/certs/server.key:1
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    dummyserver/certs/server.key.org:1
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    dummyserver/certs/server.key.org:1
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    dummyserver/certs/server.key:1
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    dummyserver/certs/client.key:1
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    dummyserver/certs/cacert.key:1
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    dummyserver/certs/cacert.key:1
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    dummyserver/certs/client.key:1
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    dummyserver/certs/server.key:1
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    dummyserver/certs/server.key.org:1
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    dummyserver/certs/cacert.key:1
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    dummyserver/certs/client.key:1
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    dummyserver/certs/server.key.org:1
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    dummyserver/certs/server.key:1
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    dummyserver/certs/cacert.key:1
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    dummyserver/certs/client.key:1
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    dummyserver/certs/server.key:1
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Serious private-key Identified a Private Key, which may compromise cryptographic security and sensitive data encryption.
    dummyserver/certs/server.key.org:1
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
… 4 more not shown

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy none found ✓

Packages you depend on that have known security holes (CVEs).

Nothing found by this check. ✓

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 59 found · 2 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious PYSEC-2016-32 The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.
    /workdirs/scan-47aba82e-9471-4f76-bb74-598cd68b337e/docs/doc-requirements.txt
    A package you depend on has a known security hole (CVE-2015-8557). Fix: Update that package to its patched version.
  • Serious PYSEC-2016-32 The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.
    /workdirs/scan-47aba82e-9471-4f76-bb74-598cd68b337e/docs/doc-requirements.txt
    A package you depend on has a known security hole (CVE-2015-8557). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2020-213 Tornado before 3.2.2 sends arbitrary responses that contain a fixed CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determin
    /workdirs/scan-47aba82e-9471-4f76-bb74-598cd68b337e/dev-requirements.txt
    A package you depend on has a known security hole (CVE-2014-9720). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-75 Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user acce
    /workdirs/scan-47aba82e-9471-4f76-bb74-598cd68b337e/dev-requirements.txt
    A package you depend on has a known security hole (CVE-2023-28370). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2025-265 Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, the supplied reason phrase is used unescaped in HTTP headers (where it could be used for header inje
    /workdirs/scan-47aba82e-9471-4f76-bb74-598cd68b337e/dev-requirements.txt
    A package you depend on has a known security hole (CVE-2025-67724). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2025-266 Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can block the server's event loop for an extended period,
    /workdirs/scan-47aba82e-9471-4f76-bb74-598cd68b337e/dev-requirements.txt
    A package you depend on has a known security hole (CVE-2025-67725). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2025-267 Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing parameters for HTTP header values, potentially causing a DoS.
    /workdirs/scan-47aba82e-9471-4f76-bb74-598cd68b337e/dev-requirements.txt
    A package you depend on has a known security hole (CVE-2025-67726). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-140 Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting
    /workdirs/scan-47aba82e-9471-4f76-bb74-598cd68b337e/dev-requirements.txt
    A package you depend on has a known security hole (CVE-2026-31958). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1974 Tornado vulnerable to excessive logging caused by malformed multipart form data
    /workdirs/scan-47aba82e-9471-4f76-bb74-598cd68b337e/dev-requirements.txt
    A package you depend on has a known security hole (CVE-2025-47287). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1975 Tornado has an HTTP cookie parsing DoS vulnerability
    /workdirs/scan-47aba82e-9471-4f76-bb74-598cd68b337e/dev-requirements.txt
    A package you depend on has a known security hole (CVE-2024-52804). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2287 In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.
    /workdirs/scan-47aba82e-9471-4f76-bb74-598cd68b337e/dev-requirements.txt
    A package you depend on has a known security hole (CVE-2026-35536). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-3387 Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
    /workdirs/scan-47aba82e-9471-4f76-bb74-598cd68b337e/dev-requirements.txt
    A package you depend on has a known security hole (CVE-2026-49853). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-3389 tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)
    /workdirs/scan-47aba82e-9471-4f76-bb74-598cd68b337e/dev-requirements.txt
    A package you depend on has a known security hole (CVE-2026-49855). Fix: Update that package to its patched version.
  • Worth fixing GHSA-753j-mpmx-qq6g Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in tornado
    /workdirs/scan-47aba82e-9471-4f76-bb74-598cd68b337e/dev-requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-pw6j-qg29-8w7f Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse
    /workdirs/scan-47aba82e-9471-4f76-bb74-598cd68b337e/dev-requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-w235-7p84-xx57 Tornado has a CRLF injection in CurlAsyncHTTPClient headers
    /workdirs/scan-47aba82e-9471-4f76-bb74-598cd68b337e/dev-requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2022-43017 An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.
    /workdirs/scan-47aba82e-9471-4f76-bb74-598cd68b337e/dev-requirements.txt
    A package you depend on has a known security hole (CVE-2022-40898). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2018-28 The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to dis
    /workdirs/scan-47aba82e-9471-4f76-bb74-598cd68b337e/dev-requirements.txt
    A package you depend on has a known security hole (CVE-2018-18074). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-74 Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected to an HTTPS endpoint. This is a product of how we use `re
    /workdirs/scan-47aba82e-9471-4f76-bb74-598cd68b337e/dev-requirements.txt
    A package you depend on has a known security hole (CVE-2023-32681). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1872 Requests vulnerable to .netrc credentials leak via malicious URLs
    /workdirs/scan-47aba82e-9471-4f76-bb74-598cd68b337e/dev-requirements.txt
    A package you depend on has a known security hole (CVE-2024-47081). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1873 Requests `Session` object does not verify requests after making first request with verify=False
    /workdirs/scan-47aba82e-9471-4f76-bb74-598cd68b337e/dev-requirements.txt
    A package you depend on has a known security hole (CVE-2024-35195). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2275 Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system te
    /workdirs/scan-47aba82e-9471-4f76-bb74-598cd68b337e/dev-requirements.txt
    A package you depend on has a known security hole (CVE-2026-25645). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2019-217 In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.
    /workdirs/scan-47aba82e-9471-4f76-bb74-598cd68b337e/docs/doc-requirements.txt
    A package you depend on has a known security hole (CVE-2019-10906). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2019-220 In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.
    /workdirs/scan-47aba82e-9471-4f76-bb74-598cd68b337e/docs/doc-requirements.txt
    A package you depend on has a known security hole (CVE-2016-10745). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2021-66 This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the
    /workdirs/scan-47aba82e-9471-4f76-bb74-598cd68b337e/docs/doc-requirements.txt
    A package you depend on has a known security hole (CVE-2020-28493). Fix: Update that package to its patched version.
… 34 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.