Логотип exploitDog
bind:CVE-2025-66418
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-66418

Количество 5

Количество 5

ubuntu логотип

CVE-2025-66418

16 дней назад

urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-66418

16 дней назад

urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2025-66418

5 дней назад

urllib3 allows an unbounded number of links in the decompression chain

EPSS: Низкий
debian логотип

CVE-2025-66418

16 дней назад

urllib3 is a user-friendly HTTP client library for Python. Starting in ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-gm62-xv2j-4w53

16 дней назад

urllib3 allows an unbounded number of links in the decompression chain

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-66418

urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.

CVSS3: 7.5
0%
Низкий
16 дней назад
nvd логотип
CVE-2025-66418

urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.

CVSS3: 7.5
0%
Низкий
16 дней назад
msrc логотип
CVE-2025-66418

urllib3 allows an unbounded number of links in the decompression chain

0%
Низкий
5 дней назад
debian логотип
CVE-2025-66418

urllib3 is a user-friendly HTTP client library for Python. Starting in ...

CVSS3: 7.5
0%
Низкий
16 дней назад
github логотип
GHSA-gm62-xv2j-4w53

urllib3 allows an unbounded number of links in the decompression chain

0%
Низкий
16 дней назад

Уязвимостей на страницу