CVE-2025-66418
05.12.2025, 16:15
urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.Enginsight
| Vendor | Product | Version |
|---|---|---|
| python | urllib3 | 1.24 ≤ 𝑥 < 2.6.0 |
𝑥
= Vulnerable software versions
Debian Releases