CVE-2026-97688
Received Received - Intake

urllib3 Infinite Loop in Deflate Decoding

Vulnerability report for CVE-2026-97688, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: GitHub, Inc.

Description

urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the Deflate decoder retains trailing bytes as unconsumed input after reaching end-of-stream and repeatedly decodes them without progress. The issue occurs when an untrusted server sends a chunked Deflate response whose decoded body exceeds a positive finite chunk size and whose encoded body has trailing bytes, specifically a response with Transfer-Encoding: chunked and Content-Encoding: deflate, content decoding enabled, and the positive finite amt=N streaming chunk size. The attack mechanism is that a malicious server returns a compressed chunked response with trailing bytes after the Deflate stream. The impact is excessive CPU usage and a request that does not complete, and network read timeouts do not interrupt the loop because no further socket read occurs. This issue is fixed in version 2.8.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
urllib3 urllib3 to 2.8.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-835 The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects urllib3, a Python HTTP client library. It causes HTTPResponse.stream and HTTPResponse.read_chunked to enter an infinite loop when processing certain Deflate-encoded responses. The issue occurs if a malicious server sends a chunked Deflate response with trailing bytes after the compressed data. The library repeatedly decodes these trailing bytes without progress, leading to excessive CPU usage and incomplete requests.

Detection Guidance

Detecting this vulnerability requires checking if your system uses urllib3 versions between 2.6.2 and 2.8.0. Run: pip show urllib3 to check the installed version. If the version is within this range, the system is vulnerable. Monitor for excessive CPU usage or hanging requests when handling chunked Deflate responses.

Impact Analysis

The vulnerability can cause high CPU usage and prevent requests from completing. Network timeouts may not stop the loop because no further data is read from the socket. This disrupts normal application flow and can degrade performance or crash services relying on urllib3 for HTTP requests.

Compliance Impact

This vulnerability primarily impacts system availability by causing excessive CPU usage and preventing requests from completing due to an infinite loop. While it does not directly expose or leak data, prolonged resource exhaustion could interfere with logging, monitoring, or audit processes required by standards like GDPR or HIPAA. Compliance may be affected if systems fail to maintain availability or fail to log events properly due to resource exhaustion.

Mitigation Strategies

Upgrade urllib3 to version 2.8.0 or later immediately. Use pip install --upgrade urllib3. If upgrading is not possible, disable chunked Deflate response handling in urllib3 or switch to a different HTTP client library until the upgrade is completed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97688. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart