CVE-2026-97689High· 8.9▾ Twilighturllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk parser buffers the chunk-size field until newl…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 49 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk parser buffers the chunk-size field until newline or EOF without a length bound. The trigger is that a malicious server returns Transfer-Encoding: chunked followed by a very long run of bytes without a newline. The attack mechanism is that a malicious HTTP server sends a very long unterminated chunk-size line. The impact is that unbounded memory allocation can exhaust the client process. This issue is fixed in version 2.8.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-97688Medium· 6.9urllib3 is an HTTP client library for Python
CVE-2026-97687High· 7.6urllib3 is an HTTP client library for Python
CVE-2025-66418High· 7.5urllib3 is a user-friendly HTTP client library for Python
CVE-2026-44432High· 7.5urllib3 is an HTTP client library for Python
CVE-2026-21441High· 7.5urllib3 is an HTTP client library for Python
CVE-2023-43804Medium· 5.9`Cookie` HTTP header isn't stripped on cross-origin redirects