Memory Allocation Vulnerability in urllib3 HTTP Client Library for Python
CVE-2026-97689
8.9HIGH
What is CVE-2026-97689?
A vulnerability in urllib3, an HTTP client library for Python, occurs when it mishandles chunked transfer encoding. Specifically, the HTTPResponse.read_chunked and HTTPResponse.stream methods may allocate unbounded memory due to the deficient handling of the chunk-size field within the streaming chunk parser. When a malicious HTTP server sends an exceedingly long unterminated chunk-size line, this flaw can lead to significant memory exhaustion in the client process. Users are advised to upgrade to version 2.8.0 or later, where this issue has been addressed.
Affected Version(s)
urllib3 >= 1.10.3, < 2.8.0
