Memory Allocation Vulnerability in urllib3 HTTP Client Library for Python
CVE-2026-97689

8.9HIGH

Key Information:

Vendor

Urllib3

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-97689?

A vulnerability in urllib3, an HTTP client library for Python, occurs when it mishandles chunked transfer encoding. Specifically, the HTTPResponse.read_chunked and HTTPResponse.stream methods may allocate unbounded memory due to the deficient handling of the chunk-size field within the streaming chunk parser. When a malicious HTTP server sends an exceedingly long unterminated chunk-size line, this flaw can lead to significant memory exhaustion in the client process. Users are advised to upgrade to version 2.8.0 or later, where this issue has been addressed.

Affected Version(s)

urllib3 >= 1.10.3, < 2.8.0

References

CVSS V4

Score:
8.9
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.