CVE-2026-21441
HIGH 7.5urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption. Starting in version 1.22 and prior to version 2.6.3, for HTTP redirect responses, the library would read the entire response body to drain the connection and decompress the content unnecessarily. This decompression occurred even before any read methods were called, and configured read limits did not restrict the amount of decompressed data. As a result, there was no safeguard against decompression bombs. A malicious server could exploit this to trigger excessive resource consumption on the client. Applications and libraries are affected when they stream content from untrusted sources by setting `preload_content=False` when they do not disable redirects. Users should upgrade to at least urllib3 v2.6.3, in which the library does not decode content of redirect responses when `preload_content=False`. If upgrading is not immediately possible, disable redirects by setting `redirect=False` for requests to untrusted source.
Affected Applications in Environment
7
Python
11 devices
Python
vWindows 11 (26.57288.0)
1 device
python
v2.7.5-5ubuntu3
1 device
python
v2.7.5-93.el7_9
1 device
python-apt
v2.0.1ubuntu0.20.04.1
1 device
python-apt
v0.9.3.5ubuntu3
1 device
python-ldap
v0:2.4.15-2.el7
1 device
Affected Devices
15
Brians-Mac-mini.local
Mac
Kellys-MacBook-Pro-3.local
Mac
MacBook-Pro.local
Mac
a00017110-J7TV3C9HW5
Mac
a00344487-F622TJW0NM
Mac
a02235045-MX74HJV2J3
Mac
a02265864-LFW93MQ9P7
Mac
a02388352-LQ22WMQLKF
Mac
a02424859-LHV909KCR7
Mac
a02456553-G06QD7XKWW
Mac
a02513954-D2V97K4D2L
Mac
guru.cluster
Linux
mac.lan
Mac
web05
Linux
webs.usu.edu
Linux