{"id":"CVE-2026-97689","published":"2026-09-29T16:17:18.837","lastModified":"2026-09-29T17:17:16.493","description":"urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk parser buffers the chunk-size field until newline or EOF without a length bound. The trigger is that a malicious server returns Transfer-Encoding: chunked followed by a very long run of bytes without a newline. The attack mechanism is that a malicious HTTP server sends a very long unterminated chunk-size line. The impact is that unbounded memory allocation can exhaust the client process. This issue is fixed in version 2.8.0.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-770"],"vendors":[],"products":[],"references":[{"url":"https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed","tags":[]},{"url":"https://github.com/urllib3/urllib3/releases/tag/2.8.0","tags":[]},{"url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw","tags":[]}],"exploitRefs":[{"url":"https://github.com/urllib3/urllib3/commit/cd770b059b543be29298ea5c52afb0b1b090f5ed","tags":[]},{"url":"https://github.com/urllib3/urllib3/releases/tag/2.8.0","tags":[]},{"url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw","tags":[]}],"hasPoc":true,"ai":null}