urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.
History

Fri, 05 Dec 2025 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Urllib3
Urllib3 urllib3
Vendors & Products Urllib3
Urllib3 urllib3

Fri, 05 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Description urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.
Title urllib3 allows an unbounded number of links in the decompression chain
Weaknesses CWE-770
References
Metrics cvssV4_0

{'score': 8.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-12-05T16:02:15.271Z

Updated: 2025-12-05T18:15:28.505Z

Reserved: 2025-11-28T23:33:56.367Z

Link: CVE-2025-66418

cve-icon Vulnrichment

Updated: 2025-12-05T16:15:58.171Z

cve-icon NVD

Status : Received

Published: 2025-12-05T16:15:51.053

Modified: 2025-12-05T16:15:51.053

Link: CVE-2025-66418

cve-icon Redhat

No data.