CVE-2026-97688
urllib3: Chunked Deflate streaming can enter an infinite loop
urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the Deflate decoder retains trailing bytes as unconsumed input after reaching end-of-stream and repeatedly decodes them without progress. The issue occurs when an untrusted server sends a chunked Deflate response whose decoded body exceeds a positive finite chunk size and whose encoded body has trailing bytes, specifically a response with Transfer-Encoding: chunked and Content-Encoding: deflate, content decoding enabled, and the positive finite amt=N streaming chunk size. The attack mechanism is that a malicious server returns a compressed chunked response with trailing bytes after the Deflate stream. The impact is excessive CPU usage and a request that does not complete, and network read timeouts do not interrupt the loop because no further socket read occurs. This issue is fixed in version 2.8.0.
| CWE | CWE-835 |
| Vendor | urllib3 |
| Product | urllib3 |
| Published | Sep 29, 2026 |
| Last Updated | Sep 29, 2026 |
Get instant alerts for urllib3 urllib3
Be the first to know when new unknown vulnerabilities affecting urllib3 urllib3 are published โ delivered to Slack, Telegram or Discord.