CVE-2026-97688

Public on 2026-09-29
Modified on 2026-10-01
Description
urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the Deflate decoder retains trailing bytes as unconsumed input after reaching end-of-stream and repeatedly decodes them without progress. The issue occurs when an untrusted server sends a chunked Deflate response whose decoded body exceeds a positive finite chunk size and whose encoded body has trailing bytes, specifically a response with Transfer-Encoding: chunked and Content-Encoding: deflate, content decoding enabled, and the positive finite amt=N streaming chunk size. The attack mechanism is that a malicious server returns a compressed chunked response with trailing bytes after the Deflate stream. The impact is excessive CPU usage and a request that does not complete, and network read timeouts do not interrupt the loop because no further socket read occurs. This issue is fixed in version 2.8.0.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
5.3
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core python-pip Not Affected
Amazon Linux 2023 python-pip Not Affected
Amazon Linux 2027 Preview python-pip Pending Fix
Amazon Linux 2 - Core python-urllib3 Not Affected
Amazon Linux 2023 python-urllib3 Not Affected
Amazon Linux 2027 Preview python-urllib3 Pending Fix
Amazon Linux 2023 python3.11-pip Not Affected
Amazon Linux 2023 python3.12-pip Not Affected
Amazon Linux 2023 python3.13-pip Not Affected
Amazon Linux 2023 python3.14-pip Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L