Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-09264

Опубликовано: 07 мая 2026
Источник: fstec
CVSS3: 7.5
CVSS2: 7.8
EPSS Низкий

Описание

Уязвимость метода HTTPConnection.urlopen() HTTP библиотеки Urllib3 языка программирования Python связана с некорректной обработкой сильно сжатых входных данных. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, получить несанкционированный доступ к защищаемой информации

Вендор

Canonical Ltd.
Red Hat Inc.
Andrey Petrov

Наименование ПО

Ubuntu
Red Hat Enterprise Linux
OpenShift Container Platform
Red Hat Quay
Migration Toolkit for Virtualization
Red Hat OpenShift Virtualization
Red Hat Update Infrastructure for Cloud Providers
Red Hat OpenStack Platform
Migration Toolkit for Containers
Red Hat Developer Hub
Red Hat OpenShift Lightspeed
Red Hat AI Inference Server
Openshift Service Mesh
Red Hat Satellite
Red Hat Trusted Artifact Signer
Red Hat build of Quarkus Native builder
Red Hat Enterprise Linux AI
Service Telemetry Framework
External Secrets Operator for Red Hat OpenShift
Ansible Automation Platform
Pen Drive Powered by Red Hat Lightspeed
Red Hat OpenShift AI
Migration Toolkit for Applications
urllib3

Версия ПО

14.04 LTS (Ubuntu)
6 (Red Hat Enterprise Linux)
7 (Red Hat Enterprise Linux)
16.04 LTS (Ubuntu)
18.04 LTS (Ubuntu)
4 (OpenShift Container Platform)
20.04 LTS (Ubuntu)
3 (Red Hat Quay)
22.04 LTS (Ubuntu)
- (Migration Toolkit for Virtualization)
4 (Red Hat OpenShift Virtualization)
4 (Red Hat Update Infrastructure for Cloud Providers)
17.1 (Red Hat OpenStack Platform)
- (Migration Toolkit for Containers)
- (Red Hat Developer Hub)
24.04 LTS (Ubuntu)
- (Red Hat OpenShift Lightspeed)
- (Red Hat AI Inference Server)
3 (Openshift Service Mesh)
25.10 (Ubuntu)
6.18 (Red Hat Satellite)
1.3 (Red Hat Trusted Artifact Signer)
- (Red Hat build of Quarkus Native builder)
3 (Red Hat Enterprise Linux AI)
1.5 (Service Telemetry Framework)
- (External Secrets Operator for Red Hat OpenShift)
2 (Ansible Automation Platform)
- (Pen Drive Powered by Red Hat Lightspeed)
- (Red Hat OpenShift AI)
26.04 LTS (Ubuntu)
8 (Migration Toolkit for Applications)
от 2.6.0 до 2.7.0 (urllib3)
1.4 (Red Hat Trusted Artifact Signer)

Тип ПО

Операционная система
Прикладное ПО информационных систем
ПО виртуализации/ПО виртуального программно-аппаратного средства
ПО программно-аппаратного средства

Операционные системы и аппаратные платформы

Canonical Ltd. Ubuntu 14.04 LTS
Red Hat Inc. Red Hat Enterprise Linux 6
Red Hat Inc. Red Hat Enterprise Linux 7
Canonical Ltd. Ubuntu 16.04 LTS
Canonical Ltd. Ubuntu 18.04 LTS
Canonical Ltd. Ubuntu 20.04 LTS
Сообщество свободного программного обеспечения Debian GNU/Linux 11
Сообщество свободного программного обеспечения Debian GNU/Linux 12
Canonical Ltd. Ubuntu 22.04 LTS
Canonical Ltd. Ubuntu 24.04 LTS
Сообщество свободного программного обеспечения Debian GNU/Linux 13
Canonical Ltd. Ubuntu 25.10
Red Hat Inc. Red Hat Enterprise Linux AI 3
Canonical Ltd. Ubuntu 26.04 LTS

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 7,8)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 7,5)
Высокий уровень опасности (оценка CVSS 4.0 составляет 8,9)

Возможные меры по устранению уязвимости

Использование рекомендаций:
Для urllib3:
https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2026-44432
Для Ubuntu:
https://ubuntu.com/security/CVE-2026-44432

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 49%
0.0068
Низкий

7.5 High

CVSS3

7.8 High

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0.

CVSS3: 7.5
redhat
3 месяца назад

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0.

CVSS3: 7.5
nvd
3 месяца назад

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0.

CVSS3: 7.5
debian
3 месяца назад

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7 ...

CVSS3: 7.5
github
3 месяца назад

urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API

EPSS

Процентиль: 49%
0.0068
Низкий

7.5 High

CVSS3

7.8 High

CVSS2