Disclosure summary
urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk parser buffers the chunk-size field until newline or EOF without a length bound. The trigger is that a malicious server returns Transfer-Encoding: chunked followed by a very long run of bytes without a newline. The attack mechanism is that a malicious HTTP server sends a very long unterminated chunk-size line. The impact is that unbounded memory allocation can exhaust the client process. This issue is fixed in version 2.8.0.
Source-reported weakness categories
CWE-770
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-97689
Open original source · Updated Sep 30, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
GitHub Reviewed Security Advisories · GHSA-vxq7-64xx-v4gw
Open original source · Updated Sep 30, 2026
urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory
Source severity: HIGH / 8.9
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | urllib3 | >= 1.10.3, < 2.8.0 | 2.8.0 |
Original records & references
PUBLISHED 2026-09-29T12:17:18-04:00
MODIFIED 2026-09-30T15:38:27-04:00
INGESTED 2026-10-06T11:43:05-04:00