AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-97689.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 8.9CVSS 4.0 · security-advisories@github.com
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSUndergoing AnalysisModified Sep 30, 2026

Disclosure summary

urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk parser buffers the chunk-size field until newline or EOF without a length bound. The trigger is that a malicious server returns Transfer-Encoding: chunked followed by a very long run of bytes without a newline. The attack mechanism is that a malicious HTTP server sends a very long unterminated chunk-size line. The impact is that unbounded memory allocation can exhaust the client process. This issue is fixed in version 2.8.0.

Source-reported weakness categories

CWE-770

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

NIST National Vulnerability Database · NVD-CVE-2026-97689

Open original source · Updated Sep 30, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

GitHub Reviewed Security Advisories · GHSA-vxq7-64xx-v4gw

Open original source · Updated Sep 30, 2026

urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory

Source severity: HIGH / 8.9

EcosystemPackageAffected rangeFirst patched
pipurllib3>= 1.10.3, < 2.8.02.8.0

Original records & references

PUBLISHED 2026-09-29T12:17:18-04:00
MODIFIED 2026-09-30T15:38:27-04:00
INGESTED 2026-10-06T11:43:05-04:00