[pkg-vuln] CVE-2026-97688 in urllib3@2.7.0 #915

Open
opened 2026-10-01 06:01:54 +00:00 by kert · 0 comments
Owner

Severity: MEDIUM
Package: urllib3 @ 2.7.0
Fixed in: 2.8.0

urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the Deflate decoder retains trailing bytes as unconsumed input after reaching end-of-stream and repeatedly decodes them without progress. The issue occurs when an untrusted server sends a chunked Deflate response whose decoded body exceeds a positive finite chunk size and whose encoded body has trailing bytes, specifically a response with Tran

Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-97688

**Severity:** MEDIUM **Package:** `urllib3` @ `2.7.0` **Fixed in:** `2.8.0` urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the Deflate decoder retains trailing bytes as unconsumed input after reaching end-of-stream and repeatedly decodes them without progress. The issue occurs when an untrusted server sends a chunked Deflate response whose decoded body exceeds a positive finite chunk size and whose encoded body has trailing bytes, specifically a response with Tran **Reference:** https://nvd.nist.gov/vuln/detail/CVE-2026-97688
kert added this to the P21: Package Supply Chain — inventory, mirrors, drift, vuln scanning milestone 2026-10-01 06:01:54 +00:00
kert added the qualityci labels 2026-10-01 06:01:54 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: homelab/stack#915