Infinite Loop Vulnerability in Python HTTP Client Library by urllib3
CVE-2026-97688

6.9MEDIUM

Key Information:

Vendor

Urllib3

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-97688?

An infinite loop vulnerability exists in the urllib3 library affecting versions 2.6.2 through 2.8.0. This issue arises when a malicious server sends a chunked Deflate response with trailing bytes, which can lead to excessive CPU consumption and a non-completing request. The problem occurs specifically when using chunked Transfer-Encoding and Content-Encoding: deflate with enabled content decoding. Importantly, read timeouts do not mitigate the problem as no further socket reads take place once the loop is triggered. The vulnerability has been addressed and fixed in version 2.8.0.

Affected Version(s)

urllib3 >= 2.6.2, < 2.8.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.