PT-2026-102667 · Pypi · Urllib3
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
urllib3 versions 2.6.2 through 2.7.x
Description
An issue exists where
HTTPResponse.stream and HTTPResponse.read chunked can enter an infinite loop. This occurs when a server sends a chunked Deflate response (Transfer-Encoding: chunked and Content-Encoding: deflate) where the decoded body exceeds a positive finite chunk size and the encoded body contains trailing bytes. The Deflate decoder retains these trailing bytes as unconsumed input after reaching the end-of-stream and repeatedly decodes them without progress. This leads to excessive CPU usage and prevents the request from completing, as network read timeouts do not interrupt the loop since no further socket reads occur.Recommendations
Update to version 2.8.0.
Exploit
Fix
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Urllib3