PT-2026-102668 · Pypi · Urllib3

·

CVE-2026-97689

·

Published

2026-09-29

·

Updated

2026-09-30

CVSS v4.0

8.9

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions urllib3 versions 1.10.3 through 2.7.x
Description The HTTPResponse.read chunked() and HTTPResponse.stream() methods can allocate unbounded memory. This occurs because the streaming chunk parser buffers the chunk-size field without a length bound until a newline or EOF is encountered. A malicious server can trigger this by returning Transfer-Encoding: chunked followed by a very long sequence of bytes without a newline, sending an unterminated chunk-size line that can exhaust the client process memory.
Recommendations Update to version 2.8.0.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97689
GHSA-VXQ7-64XX-V4GW

Affected Products

Urllib3