urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-4421-1 python-urllib3 security update
Debian DSA Debian DSA DSA-6102-1 python-urllib3 security update
Github GHSA Github GHSA GHSA-gm62-xv2j-4w53 urllib3 allows an unbounded number of links in the decompression chain
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 17 Dec 2025 09:15:00 +0900

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 11 Dec 2025 01:15:00 +0900

Type Values Removed Values Added
First Time appeared Python
Python urllib3
CPEs cpe:2.3:a:python:urllib3:*:*:*:*:*:*:*:*
Vendors & Products Python
Python urllib3
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Sat, 06 Dec 2025 06:00:00 +0900

Type Values Removed Values Added
First Time appeared Urllib3
Urllib3 urllib3
Vendors & Products Urllib3
Urllib3 urllib3

Sat, 06 Dec 2025 02:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 06 Dec 2025 01:15:00 +0900

Type Values Removed Values Added
Description urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.
Title urllib3 allows an unbounded number of links in the decompression chain
Weaknesses CWE-770
References
Metrics cvssV4_0

{'score': 8.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-12-05T18:15:28.505Z

Reserved: 2025-11-28T23:33:56.367Z

Link: CVE-2025-66418

cve-icon Vulnrichment

Updated: 2025-12-05T16:15:58.171Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-05T16:15:51.053

Modified: 2025-12-10T16:08:32.193

Link: CVE-2025-66418

cve-icon Redhat

Severity : Important

Publid Date: 2025-12-05T16:02:15Z

Links: CVE-2025-66418 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2025-12-06T05:56:15Z

Weaknesses