CVE-2026-97689: fallo de gravedad alta en urllib3
urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory
Publicada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.9epss 0.3%
probabilidad de explotación
0.3%top 80% de las CVE
explotación observada
noninguna fuente lo reporta
urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk parser buffers the chunk-size field until newline or EOF without a length bound. The trigger is that a malicious server returns Transfer-Encoding: chunked followed by a very long run of bytes without a newline. The attack mechanism is that a malicious HTTP server sends a very long unterminated chunk-size line. The impact is that unbounded memory allocation can exhaust the client process. This issue is fixed in version 2.8.0.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
Productos afectados
urllib3 · urllib3CVEs relacionadas — urllib3
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-21441HIGHurllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)EPSS 2.9%CVE-2023-43804MEDIUM`Cookie` HTTP header isn't stripped on cross-origin redirectsEPSS 1.4%CVE-2024-37891MEDIUMProxy-Authorization request header isn't stripped during cross-origin redirects in urllib3EPSS 1.1%CVE-2026-44432HIGHurllib3: Decompression-bomb safeguards bypassed in parts of the streaming APIEPSS 0.9%CVE-2025-66471HIGHurllib3 Streaming API improperly handles highly compressed dataEPSS 0.7%CVE-2025-66418HIGHurllib3 allows an unbounded number of links in the decompression chainEPSS 0.7%