PT-2026-102667 · Pypi · Urllib3

·

CVE-2026-97688

·

Published

2026-09-29

·

Updated

2026-09-30

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions urllib3 versions 2.6.2 through 2.7.x
Description An issue exists where HTTPResponse.stream and HTTPResponse.read chunked can enter an infinite loop. This occurs when a server sends a chunked Deflate response (Transfer-Encoding: chunked and Content-Encoding: deflate) where the decoded body exceeds a positive finite chunk size and the encoded body contains trailing bytes. The Deflate decoder retains these trailing bytes as unconsumed input after reaching the end-of-stream and repeatedly decodes them without progress. This leads to excessive CPU usage and prevents the request from completing, as network read timeouts do not interrupt the loop since no further socket reads occur.
Recommendations Update to version 2.8.0.

Exploit

Fix

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97688
GHSA-GH4C-6FX4-QH6G

Affected Products

Urllib3