๐Ÿ” CVE Alert

CVE-2026-97689

UNKNOWN 0.0

urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk parser buffers the chunk-size field until newline or EOF without a length bound. The trigger is that a malicious server returns Transfer-Encoding: chunked followed by a very long run of bytes without a newline. The attack mechanism is that a malicious HTTP server sends a very long unterminated chunk-size line. The impact is that unbounded memory allocation can exhaust the client process. This issue is fixed in version 2.8.0.

CWE CWE-770
Vendor urllib3
Product urllib3
Published Sep 29, 2026
Last Updated Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for urllib3 urllib3

Be the first to know when new unknown vulnerabilities affecting urllib3 urllib3 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

urllib3 / urllib3
>= 1.10.3, < 2.8.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw github.com: https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed github.com: https://github.com/urllib3/urllib3/releases/tag/2.8.0