Infinite Loop Vulnerability in Python HTTP Client Library by urllib3
CVE-2026-97688
6.9MEDIUM
What is CVE-2026-97688?
An infinite loop vulnerability exists in the urllib3 library affecting versions 2.6.2 through 2.8.0. This issue arises when a malicious server sends a chunked Deflate response with trailing bytes, which can lead to excessive CPU consumption and a non-completing request. The problem occurs specifically when using chunked Transfer-Encoding and Content-Encoding: deflate with enabled content decoding. Importantly, read timeouts do not mitigate the problem as no further socket reads take place once the loop is triggered. The vulnerability has been addressed and fixed in version 2.8.0.
Affected Version(s)
urllib3 >= 2.6.2, < 2.8.0
