DirectorySecurity AdvisoriesPricing
/
Sign in
Security Advisories

CVE-2025-66418

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2025-66418

Severity

Unknown

Summary

urllib3 allows an unbounded number of links in the decompression chain

Description

urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing