CVE-2026-44432

EUVD-2026-30047
urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0.
Data Amplification
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 49.06%
Affected Products (NVD)
VendorProductVersion
pythonurllib3
2.6.0 ≤
𝑥
< 2.7.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8
0:4.6.30-2.el8ap ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9
0:4.6.30-2.el9ap ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.6 for RHEL 9
0:2.7.0-1.el9ap ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.6 for RHEL 9
0:4.7.14-3.el9ap ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 10
0:2.6.3-2.el10_2 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 10
0:1.26.19-4.el10_2 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 8
0:1.26.19-3.el8_10 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9
0:2.6.3-2.el9_8 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9
0:1.26.19-3.el9_8 ≤
𝑥
< *
ADP
Red HatRed Hat Enterprise Linux 9
0:1.26.5-8.el9_8 ≤
𝑥
< *
ADP
Red HatRed Hat AI Inference Server 3.3
1782352950 ≤
𝑥
< *
ADP
Red HatRed Hat AI Inference Server 3.3
1782352919 ≤
𝑥
< *
ADP
Red HatRed Hat AI Inference Server 3.3
1782353093 ≤
𝑥
< *
ADP
Red HatRed Hat AI Inference Server 3.3
1782352847 ≤
𝑥
< *
ADP
Red HatRed Hat AI Inference Server 3.4
1780356811 ≤
𝑥
< *
ADP
Red HatRed Hat AI Inference Server 3.4
1780356904 ≤
𝑥
< *
ADP
Red HatRed Hat AI Inference Server 3.4
1780356941 ≤
𝑥
< *
ADP
Red HatRed Hat AI Inference Server 3.4
1780356914 ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.5
1784050598 ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.6
1782761510 ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.6
1782650747 ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.6
1783973764 ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.6
1783921549 ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.6
1783923629 ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.6
1783969139 ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.7
1781028735 ≤
𝑥
< *
ADP
Red HatRed Hat Ansible Automation Platform 2.7
1781102816 ≤
𝑥
< *
ADP
Red HatRed Hat Discovery 2
1779395228 ≤
𝑥
< *
ADP
Red HatRed Hat Discovery 2
1782756541 ≤
𝑥
< *
ADP
Red HatRed Hat Hardened Images
0.69.3-1.2.hum1 ≤
𝑥
< *
ADP
Red HatRed Hat Hardened Images
1.96.0-1.hum1 ≤
𝑥
< *
ADP
Red HatRed Hat Hardened Images
1.2.1-2.hum1 ≤
𝑥
< *
ADP
Red HatRed Hat Hardened Images
2.7.0-3.hum1 ≤
𝑥
< *
ADP
Red HatRed Hat Hardened Images
48.0.0-3.hum1 ≤
𝑥
< *
ADP
Red HatRed Hat Hardened Images
21.1.8-6.hum1 ≤
𝑥
< *
ADP
Red HatRed Hat Hardened Images
2026.5.1-1.hum1 ≤
𝑥
< *
ADP
Red HatRed Hat Hardened Images
2.19.0-1.hum1 ≤
𝑥
< *
ADP
Red HatRed Hat Hardened Images
11.8.8-1.hum1 ≤
𝑥
< *
ADP
Red HatRed Hat Hardened Images
2.48.0-4.1.hum1 ≤
𝑥
< *
ADP
Red HatRed Hat Hardened Images
21.1.8-1.1.hum1 ≤
𝑥
< *
ADP
Red HatRed Hat Migration Toolkit for Applications 8.2
1784109883 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 2.25
1783024305 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 2.25
1783701598 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 2.25
1783342900 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 2.25
1783112979 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 2.25
1783091175 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 2.25
1783998774 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 2.25
1783998857 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 3.3
1783010225 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 3.3
1782917849 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 3.3
1782887848 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 3.3
1782854229 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 3.3
1782471555 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 3.3
1782471579 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 3.3
1783073038 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 3.3
1782991170 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 3.3
1782471656 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 3.3
1782471663 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 3.3
1783069204 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 3.3
1782991170 ≤
𝑥
< *
ADP
Red HatRed Hat OpenShift AI 3.3
1782472374 ≤
𝑥
< *
ADP
Red HatRed Hat Quay 3.1
1782487717 ≤
𝑥
< *
ADP
Red HatRed Hat Quay 3.12
1781937357 ≤
𝑥
< *
ADP
Red HatRed Hat Quay 3.15
1784351966 ≤
𝑥
< *
ADP
Red HatRed Hat Quay 3.16
1783955846 ≤
𝑥
< *
ADP
Red HatRed Hat Quay 3.9
1781878070 ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.18
1779792651 ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.18
1779711334 ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.18
1782739344 ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.19
1782139619 ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.19
1780393451 ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.19
1782380482 ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.19
1782448455 ≤
𝑥
< *
ADP
Red HatRed Hat Satellite 6.19
1784558259 ≤
𝑥
< *
ADP
Red HatRed Hat Trusted Artifact Signer 1.3
1780560117 ≤
𝑥
< *
ADP
Red HatRed Hat Trusted Artifact Signer 1.4
1780914886 ≤
𝑥
< *
ADP
Red HatRed Hat Update Infrastructure 5
1784794818 ≤
𝑥
< *
ADP
Red HatRed Hat Update Infrastructure 5
1784794778 ≤
𝑥
< *
ADP
Red HatRed Hat Update Infrastructure 5
1784795112 ≤
𝑥
< *
ADP
Red HatRed Hat Update Infrastructure 5
1784794289 ≤
𝑥
< *
ADP
Red HatRed Hat Update Infrastructure 5
1784795076 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
python-urllib3
bookworm
1.26.12-1+deb12u4
fixed
bookworm (security)
1.26.12-1+deb12u4
fixed
bullseye
1.26.5-1~exp1
fixed
bullseye (security)
1.26.5-1~exp1+deb11u4
fixed
forky
2.7.0-3
fixed
sid
2.7.0-3
fixed
trixie
2.3.0-3+deb13u2
fixed
trixie (security)
2.3.0-3+deb13u2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python-pip
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
trusty
needs-triage
python-urllib3
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
questing
not-affected
resolute
Fixed 2.6.3-1ubuntu1.1
released
trusty
not-affected
xenial
not-affected
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
python3-urllib3
RHEL 9
0:1.26.5-8.el9_8
fixed
python3.12-urllib3
RHEL 9
0:1.26.19-3.el9_8
fixed
python3.14-urllib3
RHEL 9
0:2.6.3-2.el9_8
fixed
References