PT-2025-49260 · Pypi+6 · Urllib3+6

Published

2025-01-01

·

Updated

2026-05-28

·

CVE-2025-66418

CVSS v4.0

8.9

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
Name of the Vulnerable Software and Affected Versions urllib3 versions 1.24 through 2.5.9
Description urllib3 is a user-friendly HTTP client library for Python. In versions starting from 1.24 and prior to 2.6.0, the decompression chain had an unbounded number of links. This allowed a malicious server to insert a virtually unlimited number of compression steps, leading to high CPU usage and substantial memory allocation during decompression of the data. This issue can potentially lead to denial-of-service conditions.
Recommendations urllib3 versions prior to 2.6.0 should be updated to version 2.6.0 or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

ALSA-2026:1086
ALSA-2026:1087
ALSA-2026:1088
ALSA-2026:1089
ALSA-2026:1224
ALSA-2026:1226
ALSA-2026:1239
ALSA-2026:1240
ALSA-2026:1241
ALSA-2026:1254
AZL-71834
AZL-71846
BDU:2026-02927
CVE-2025-66418
DLA-4421-1
ECHO-2D1B-2193-003F
GHSA-GM62-XV2J-4W53
MGASA-2026-0011
OESA-2026-1233
OESA-2026-1234
OESA-2026-1235
OESA-2026-1251
OESA-2026-1252
OESA-2026-1253
OESA-2026-1332
OESA-2026-1333
OESA-2026-1347
OPENSUSE-SU-2026:10026-1
OPENSUSE-SU-2026:10096-1
OPENSUSE-SU-2026:10431-1
OPENSUSE-SU-2026:10539-1
OPENSUSE-SU-2026:20127-1
OPENSUSE-SU-2026:20271-1
RHSA-2026:1086
RHSA-2026:1087
RHSA-2026:1088
RHSA-2026:1089
RHSA-2026:1224
RHSA-2026:1226
RHSA-2026:1239
RHSA-2026:1240
RHSA-2026:1241
RHSA-2026:1254
RHSA-2026:1329
RHSA-2026:1330
RHSA-2026:1331
RHSA-2026:1332
RHSA-2026:1336
RHSA-2026:1337
RHSA-2026:1338
RHSA-2026:1339
RHSA-2026:1340
RHSA-2026:1485
RHSA-2026:1546
RHSA-2026:1618
RHSA-2026:1619
RHSA-2026:1674
RHSA-2026:1676
RHSA-2026:1693
RHSA-2026:1701
RHSA-2026:1702
RHSA-2026:1704
RHSA-2026:1712
RHSA-2026:1726
RHSA-2026:1729
RHSA-2026:1957
RHSA-2026:2279
RHSA-2026:2717
RHSA-2026:2718
RHSA-2026:2723
RHSA-2026:2728
RHSA-2026:2764
RHSA-2026:2765
SUSE-SU-2026:0367-1
SUSE-SU-2026:0443-1
SUSE-SU-2026:0635-1
SUSE-SU-2026:1412-1
SUSE-SU-2026:20175-1
SUSE-SU-2026:20189-1
SUSE-SU-2026:20443-1
SUSE-SU-2026:20485-1
SUSE-SU-2026:20591-1
USN-7927-1
USN-8010-1
USN-8344-1

Affected Products

Alt Linux
Debian
Linuxmint
Red Os
Rocky Linux
Ubuntu
Urllib3