CVE-2026-97689highCWE-770

CVE-2026-97689: high-severity vulnerability in urllib3

urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory

Published

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.9epss 0.3%
exploitation probability
0.3%top 80% of all CVEs
observed exploitation
nono source reports it
urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk parser buffers the chunk-size field until newline or EOF without a length bound. The trigger is that a malicious server returns Transfer-Encoding: chunked followed by a very long run of bytes without a newline. The attack mechanism is that a malicious HTTP server sends a very long unterminated chunk-size line. The impact is that unbounded memory allocation can exhaust the client process. This issue is fixed in version 2.8.0.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
Affected products
urllib3 · urllib3