๐Ÿ” CVE Alert

CVE-2026-97688

UNKNOWN 0.0

urllib3: Chunked Deflate streaming can enter an infinite loop

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the Deflate decoder retains trailing bytes as unconsumed input after reaching end-of-stream and repeatedly decodes them without progress. The issue occurs when an untrusted server sends a chunked Deflate response whose decoded body exceeds a positive finite chunk size and whose encoded body has trailing bytes, specifically a response with Transfer-Encoding: chunked and Content-Encoding: deflate, content decoding enabled, and the positive finite amt=N streaming chunk size. The attack mechanism is that a malicious server returns a compressed chunked response with trailing bytes after the Deflate stream. The impact is excessive CPU usage and a request that does not complete, and network read timeouts do not interrupt the loop because no further socket read occurs. This issue is fixed in version 2.8.0.

CWE CWE-835
Vendor urllib3
Product urllib3
Published Sep 29, 2026
Last Updated Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for urllib3 urllib3

Be the first to know when new unknown vulnerabilities affecting urllib3 urllib3 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

urllib3 / urllib3
>= 2.6.2, < 2.8.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g github.com: https://github.com/urllib3/urllib3/commit/ea2ad7b21a80da3632f80016526a18864586077f github.com: https://github.com/urllib3/urllib3/releases/tag/2.8.0