Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:0255-1

Опубликовано: 22 янв. 2026
Источник: suse-cvrf

Описание

Security update for python-urllib3

This update for python-urllib3 fixes the following issues:

  • CVE-2026-21441: Fixed excessive resource consumption during decompression of data in HTTP redirect responses (bsc#1256331)

Список пакетов

Image SLES15-SP4-BYOS
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP4-BYOS-Azure
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP4-BYOS-EC2
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP4-Hardened-BYOS
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP4-Hardened-BYOS-Azure
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP4-SAP-BYOS
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP4-SAP-BYOS-Azure
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP4-SAP-BYOS-EC2
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP4-SAP-Hardened-BYOS
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP4-SAP-Hardened-BYOS-Azure
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP5-Azure-3P
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP5-BYOS-Azure
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP5-BYOS-EC2
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP5-Hardened-BYOS-Azure
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP5-Hardened-BYOS-EC2
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP5-SAP-Azure-3P
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP5-SAP-BYOS-Azure
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP5-SAP-BYOS-EC2
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP5-SAP-Hardened-Azure
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP5-SAP-Hardened-BYOS-Azure
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP5-SAP-Hardened-BYOS-EC2
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP6
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP6-Azure-3P
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP6-Azure-Standard
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP6-BYOS
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP6-BYOS-Azure
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP6-BYOS-EC2
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP6-Hardened-BYOS
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP6-Hardened-BYOS-Azure
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP6-SAP
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP6-SAP-Azure
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP6-SAP-Azure-3P
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP6-SAP-BYOS-Azure
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP6-SAP-Hardened
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP6-SAP-Hardened-Azure
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP6-SAP-Hardened-BYOS
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP6-SAP-Hardened-BYOS-Azure
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP6-SAP-Hardened-BYOS-EC2
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP6-SAP-Hardened-EC2
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP6-SAPCAL
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP6-SAPCAL-Azure
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP7-Azure-3P
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP7-Azure-Basic
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP7-Azure-Standard
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP7-BYOS-Azure
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP7-BYOS-EC2
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP7-BYOS-GCE
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP7-HPC-Azure
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP7-HPC-BYOS-Azure
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP7-HPC-BYOS-EC2
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP7-HPC-BYOS-GCE
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP7-Hardened-BYOS-Azure
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP7-Hardened-BYOS-EC2
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP7-Hardened-BYOS-GCE
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP7-SAP-Azure
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP7-SAP-Azure-3P
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP7-SAP-BYOS-Azure
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP7-SAP-BYOS-GCE
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP7-SAP-EC2
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP7-SAP-Hardened-Azure
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP7-SAP-Hardened-BYOS-Azure
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP7-SAP-Hardened-BYOS-EC2
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP7-SAP-Hardened-BYOS-GCE
python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP7-SAPCAL-Azure
python311-urllib3-2.0.7-150400.7.24.1
SUSE Linux Enterprise Module for Public Cloud 15 SP4
python311-urllib3-2.0.7-150400.7.24.1
SUSE Linux Enterprise Module for Python 3 15 SP7
python311-urllib3-2.0.7-150400.7.24.1
openSUSE Leap 15.6
python311-urllib3-2.0.7-150400.7.24.1

Описание

urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption. Starting in version 1.22 and prior to version 2.6.3, for HTTP redirect responses, the library would read the entire response body to drain the connection and decompress the content unnecessarily. This decompression occurred even before any read methods were called, and configured read limits did not restrict the amount of decompressed data. As a result, there was no safeguard against decompression bombs. A malicious server could exploit this to trigger excessive resource consumption on the client. Applications and libraries are affected when they stream content from untrusted sources by setting `preload_content=False` when they do not disable redirects. Users should upgrade to at least urllib3 v2.6.3, in which the library does not decode content of redirect responses when `preload_content=False`. If upgrading is not immediately possible, disable redirects by setting `redirect=False` for requests to untrusted source.


Затронутые продукты
Image SLES15-SP4-BYOS-Azure:python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP4-BYOS-EC2:python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP4-BYOS:python311-urllib3-2.0.7-150400.7.24.1
Image SLES15-SP4-Hardened-BYOS-Azure:python311-urllib3-2.0.7-150400.7.24.1

Ссылки