CVE-2026-97688: medium-severity vulnerability in urllib3
urllib3: Chunked Deflate streaming can enter an infinite loop
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.9epss 0.3%
exploitation probability
0.3%top 80% of all CVEs
observed exploitation
nono source reports it
urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the Deflate decoder retains trailing bytes as unconsumed input after reaching end-of-stream and repeatedly decodes them without progress. The issue occurs when an untrusted server sends a chunked Deflate response whose decoded body exceeds a positive finite chunk size and whose encoded body has trailing bytes, specifically a response with Transfer-Encoding: chunked and Content-Encoding: deflate, content decoding enabled, and the positive finite amt=N streaming chunk size. The attack mechanism is that a malicious server returns a compressed chunked response with trailing bytes after the Deflate stream. The impact is excessive CPU usage and a request that does not complete, and network read timeouts do not interrupt the loop because no further socket read occurs. This issue is fixed in version 2.8.0.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Affected products
urllib3 · urllib3Related CVEs — urllib3
In the same product, most dangerous first.
CVE-2026-21441HIGHurllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)EPSS 2.9%CVE-2023-43804MEDIUM`Cookie` HTTP header isn't stripped on cross-origin redirectsEPSS 1.4%CVE-2024-37891MEDIUMProxy-Authorization request header isn't stripped during cross-origin redirects in urllib3EPSS 1.1%CVE-2026-44432HIGHurllib3: Decompression-bomb safeguards bypassed in parts of the streaming APIEPSS 0.9%CVE-2025-66471HIGHurllib3 Streaming API improperly handles highly compressed dataEPSS 0.7%CVE-2025-66418HIGHurllib3 allows an unbounded number of links in the decompression chainEPSS 0.7%