PT-2026-56548 · Pypi+3 · Httplib2+3

CVE-2026-59939

·

Published

2026-07-08

·

Updated

2026-08-31

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions httplib2 versions prior to 0.32.0
Description An issue exists where the library performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate within the decompressContent() function in httplib2/init.py. A malicious or compromised HTTP server can return a small compressed payload, known as a decompression bomb, that expands to an arbitrarily large size in memory. This uncontrolled resource consumption can lead to a MemoryError or cause the client process to be OOM-killed (Out-Of-Memory killed), resulting in a denial-of-service.
Recommendations Update to version 0.32.0.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:47736
ALSA-2026:48585
ALSA-2026:50317
AZL-92295
CVE-2026-59939
ECHO-CCAD-6619-0A54
GHSA-J5G9-F88F-GFJ3
OPENSUSE-SU-2026:21526-1
PYSEC-2026-3444
RHSA-2026:47736
RHSA-2026:48585
RHSA-2026:48604
RHSA-2026:48605
RHSA-2026:48615
RHSA-2026:49911
RHSA-2026:50317
RHSA-2026:50653
RHSA-2026:50654
RHSA-2026:50655
SUSE-SU-2026:23120-1
SUSE-SU-2026:23142-1
SUSE-SU-2026:3898-1
USN-8537-1

Affected Products

Linuxmint
Rocky Linux
Ubuntu
Httplib2