Количество 8
Количество 8
CVE-2026-9375
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-9375
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
openSUSE-SU-2026:21430-1
Security update for python-urllib3
SUSE-SU-2026:3397-1
Security update for python-urllib3
ROS-20260908-80-0061
Уязвимость python-idna
ROS-20260908-80-0060
Уязвимость python-trustme
ROS-20260908-80-0059
Уязвимость pyOpenSSL
GHSA-mwq6-fg78-p6cq
urllib3 version 2.6.3 is vulnerable to a decompression bomb bypass in its streaming API (`preload_content=False`) when using Brotli support. The issue arises due to three independent code paths in `response.py` that bypass the `max_length` protection introduced in version 2.6.0 to mitigate CVE-2025-66471. Specifically, negative `max_length` values can be produced due to buffer arithmetic in `read()`, `flush_decoder` unconditionally overrides `max_length` to `-1`, and `_flush_decoder()` passes no limit at all, defaulting to unlimited decompression. This allows a malicious HTTP server to trigger an out-of-memory (OOM) condition by decompressing large payloads into memory, leading to a denial of service (DoS). The vulnerability affects urllib3 2.6.3 and Brotli 1.2.0 and impacts applications and libraries using `requests` or `urllib3` to stream content from untrusted sources.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-9375 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | 3 месяца назад | |||
CVE-2026-9375 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | 3 месяца назад | |||
openSUSE-SU-2026:21430-1 Security update for python-urllib3 | около 2 месяцев назад | |||
SUSE-SU-2026:3397-1 Security update for python-urllib3 | около 2 месяцев назад | |||
ROS-20260908-80-0061 Уязвимость python-idna | CVSS2: 7.8 | 10 дней назад | ||
ROS-20260908-80-0060 Уязвимость python-trustme | CVSS2: 7.8 | 10 дней назад | ||
ROS-20260908-80-0059 Уязвимость pyOpenSSL | CVSS2: 7.8 | 10 дней назад | ||
GHSA-mwq6-fg78-p6cq urllib3 version 2.6.3 is vulnerable to a decompression bomb bypass in its streaming API (`preload_content=False`) when using Brotli support. The issue arises due to three independent code paths in `response.py` that bypass the `max_length` protection introduced in version 2.6.0 to mitigate CVE-2025-66471. Specifically, negative `max_length` values can be produced due to buffer arithmetic in `read()`, `flush_decoder` unconditionally overrides `max_length` to `-1`, and `_flush_decoder()` passes no limit at all, defaulting to unlimited decompression. This allows a malicious HTTP server to trigger an out-of-memory (OOM) condition by decompressing large payloads into memory, leading to a denial of service (DoS). The vulnerability affects urllib3 2.6.3 and Brotli 1.2.0 and impacts applications and libraries using `requests` or `urllib3` to stream content from untrusted sources. | CVSS3: 7.5 | 3 месяца назад |
Уязвимостей на страницу