Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-44432

Опубликовано: 13 мая 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 7.5

Описание

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0.

РелизСтатусПримечание
devel

needs-triage

esm-apps-legacy/xenial

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/resolute

needs-triage

esm-infra-legacy/trusty

needs-triage

jammy

needs-triage

noble

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

2.6.3-2ubuntu1
esm-infra-legacy/trusty

not-affected

code not present
esm-infra-legacy/xenial

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
jammy

not-affected

1.26.5-1~exp1ubuntu0.6
noble

not-affected

2.0.7-1ubuntu0.6
questing

not-affected

2.3.0-3ubuntu0.4
resolute

released

2.6.3-1ubuntu1.1
upstream

released

2.7.0

Показывать по

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
3 месяца назад

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0.

CVSS3: 7.5
nvd
3 месяца назад

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0.

CVSS3: 7.5
debian
3 месяца назад

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7 ...

CVSS3: 7.5
github
3 месяца назад

urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API

CVSS3: 7.5
fstec
3 месяца назад

Уязвимость потокового прикладного интерфейса обработки ответов HTTP библиотеки Urllib3 языка программирования Python, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3