Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59939

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allowing a malicious or compromised HTTP server to return a small compressed payload that expands to an arbitrarily large size in memory and causes MemoryError or OOM-kill in the client process. This issue is fixed in version 0.32.0.

A flaw was found in httplib2, a Python HTTP client library. This vulnerability allows a malicious or compromised HTTP server to send a small compressed data payload that, when decompressed by httplib2, expands to an extremely large size in memory. This unbounded decompression can lead to a Denial of Service (DoS) by causing the client application to run out of memory and crash.

Отчет

This Important vulnerability in httplib2 allows a remote attacker to trigger a Denial of Service (DoS) in client applications. By sending a specially crafted, compressed HTTP response, a malicious server can cause the client to exhaust its memory due to unbounded decompression, leading to application crashes. This poses a significant risk to Red Hat products that use httplib2 to process untrusted HTTP content.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/lightspeed-rhel8Will not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-rhel8Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/lightspeed-rhel9Affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/lightspeed-rhel9Affected
Red Hat Enterprise Linux 10fence-agentsAffected
Red Hat Enterprise Linux 7fence-agentsOut of support scope
Red Hat Enterprise Linux 8fence-agentsAffected
Red Hat Enterprise Linux 9fence-agentsAffected
Red Hat Hardened Imagesmariadb11.8Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-trustyai-garak-lls-provider-dsp-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-409
https://bugzilla.redhat.com/show_bug.cgi?id=2498212httplib2: httplib2: Denial of Service via unbounded decompression of HTTP response bodies

EPSS

Процентиль: 34%
0.0041
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
26 дней назад

httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allowing a malicious or compromised HTTP server to return a small compressed payload that expands to an arbitrarily large size in memory and causes MemoryError or OOM-kill in the client process. This issue is fixed in version 0.32.0.

CVSS3: 7.5
nvd
26 дней назад

httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allowing a malicious or compromised HTTP server to return a small compressed payload that expands to an arbitrarily large size in memory and causes MemoryError or OOM-kill in the client process. This issue is fixed in version 0.32.0.

CVSS3: 7.5
debian
26 дней назад

httplib2 is a comprehensive HTTP client library for Python. Prior to 0 ...

CVSS3: 7.5
github
10 дней назад

httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling

EPSS

Процентиль: 34%
0.0041
Низкий

7.5 High

CVSS3