PT-2026-2060 · Pypi+5 · Urllib3+5

Illia-V

+1

·

Published

2026-01-07

·

Updated

2026-05-20

·

CVE-2026-21441

CVSS v4.0

8.9

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
Name of the Vulnerable Software and Affected Versions urllib3 versions 1.22 through 2.6.2
Description urllib3 is a Python HTTP client library. Its streaming API is designed for efficient handling of large HTTP responses by reading content in chunks. The library decompresses content based on the HTTP Content-Encoding header, such as gzip, deflate, br, or zstd. When using the streaming API with HTTP redirects and preload content set to False, versions prior to 2.6.3 would unnecessarily read and decompress the entire response body, even before any read methods were called. Configured read limits did not restrict the amount of decompressed data, creating a risk of decompression bombs. A malicious server could exploit this to cause excessive resource consumption on the client. Applications and libraries are affected when streaming content from untrusted sources without disabling redirects.
Recommendations Upgrade to urllib3 version 2.6.3 or later. If upgrading is not immediately possible, disable redirects by setting redirect=False for requests to untrusted sources.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

ALSA-2026:1086
ALSA-2026:1087
ALSA-2026:1088
ALSA-2026:1089
ALSA-2026:1224
ALSA-2026:1226
ALSA-2026:1239
ALSA-2026:1240
ALSA-2026:1241
ALSA-2026:1254
AZL-73730
AZL-73734
AZL-74153
BDU:2026-03625
CVE-2026-21441
ECHO-48C0-4C3C-3A0D
GHSA-38JV-5279-WG99
MGASA-2026-0011
OESA-2026-1287
OESA-2026-1288
OESA-2026-1289
OESA-2026-1290
OESA-2026-1346
OESA-2026-1347
OESA-2026-1443
OESA-2026-1444
OESA-2026-1445
OESA-2026-1447
OESA-2026-1448
OPENSUSE-SU-2026:10049-1
OPENSUSE-SU-2026:10096-1
OPENSUSE-SU-2026:10539-1
OPENSUSE-SU-2026:20088-1
OPENSUSE-SU-2026:20271-1
RHSA-2026:1086
RHSA-2026:1087
RHSA-2026:1088
RHSA-2026:1089
RHSA-2026:1224
RHSA-2026:1226
RHSA-2026:1239
RHSA-2026:1240
RHSA-2026:1241
RHSA-2026:1254
RHSA-2026:1485
RHSA-2026:1546
RHSA-2026:1618
RHSA-2026:1619
RHSA-2026:1674
RHSA-2026:1676
RHSA-2026:1693
RHSA-2026:1704
RHSA-2026:1706
RHSA-2026:1712
RHSA-2026:1717
RHSA-2026:1726
RHSA-2026:1729
RHSA-2026:1734
RHSA-2026:1735
RHSA-2026:1791
RHSA-2026:1792
RHSA-2026:1793
RHSA-2026:1794
RHSA-2026:1803
RHSA-2026:1805
RHSA-2026:1957
RHSA-2026:2717
RHSA-2026:2718
RHSA-2026:2723
RHSA-2026:2728
RHSA-2026:2760
RHSA-2026:2764
RHSA-2026:2765
RHSA-2026:2911
SUSE-SU-2026:0255-1
SUSE-SU-2026:0443-1
SUSE-SU-2026:0635-1
SUSE-SU-2026:1412-1
SUSE-SU-2026:20131-1
SUSE-SU-2026:20157-1
SUSE-SU-2026:20270-1
SUSE-SU-2026:20364-1
SUSE-SU-2026:20591-1
USN-7955-1
USN-7955-2
USN-8010-1

Affected Products

Debian
Linuxmint
Red Os
Rocky Linux
Ubuntu
Urllib3