Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 29 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Urllib3
Urllib3 urllib3 |
|
| Vendors & Products |
Urllib3
Urllib3 urllib3 |
|
| Metrics |
ssvc
|
Tue, 29 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk parser buffers the chunk-size field until newline or EOF without a length bound. The trigger is that a malicious server returns Transfer-Encoding: chunked followed by a very long run of bytes without a newline. The attack mechanism is that a malicious HTTP server sends a very long unterminated chunk-size line. The impact is that unbounded memory allocation can exhaust the client process. This issue is fixed in version 2.8.0. | |
| Title | urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-29T16:23:23.167Z
Reserved: 2026-09-24T21:43:37.208Z
Link: CVE-2026-97689
Updated: 2026-09-29T16:23:05.435Z
Status : Received
Published: 2026-09-29T16:17:18.837
Modified: 2026-09-29T17:17:16.493
Link: CVE-2026-97689
No data.
OpenCVE Enrichment
Updated: 2026-09-29T17:15:08Z