[pkg-vuln] CVE-2026-97689 in urllib3@2.7.0 #914

Open
opened 2026-10-01 06:01:54 +00:00 by kert · 0 comments
Owner

Severity: HIGH
Package: urllib3 @ 2.7.0
Fixed in: 2.8.0

urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk parser buffers the chunk-size field until newline or EOF without a length bound. The trigger is that a malicious server returns Transfer-Encoding: chunked followed by a very long run of bytes without a newline. The attack mechanism is that a malicious HTTP server sends a very long unterminated chunk-size lin

Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-97689

**Severity:** HIGH **Package:** `urllib3` @ `2.7.0` **Fixed in:** `2.8.0` urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk parser buffers the chunk-size field until newline or EOF without a length bound. The trigger is that a malicious server returns Transfer-Encoding: chunked followed by a very long run of bytes without a newline. The attack mechanism is that a malicious HTTP server sends a very long unterminated chunk-size lin **Reference:** https://nvd.nist.gov/vuln/detail/CVE-2026-97689
kert added this to the P21: Package Supply Chain — inventory, mirrors, drift, vuln scanning milestone 2026-10-01 06:01:54 +00:00
kert added the qualityci labels 2026-10-01 06:01:54 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: homelab/stack#914