PT-2025-49260 · Pypi+6 · Urllib3+6
Published
2025-01-01
·
Updated
2026-05-28
·
CVE-2025-66418
CVSS v4.0
8.9
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H |
Name of the Vulnerable Software and Affected Versions
urllib3 versions 1.24 through 2.5.9
Description
urllib3 is a user-friendly HTTP client library for Python. In versions starting from 1.24 and prior to 2.6.0, the decompression chain had an unbounded number of links. This allowed a malicious server to insert a virtually unlimited number of compression steps, leading to high CPU usage and substantial memory allocation during decompression of the data. This issue can potentially lead to denial-of-service conditions.
Recommendations
urllib3 versions prior to 2.6.0 should be updated to version 2.6.0 or later.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Linuxmint
Red Os
Rocky Linux
Ubuntu
Urllib3