216.73.216.233

CVE-2025-66418

· Published 05/12/2025 16:15 · Modified 10/12/2025 16:08

Labels: CVE-2025-66418 2025-12-05CVE-2025-66418CWE-770[email protected]

Essential information

Published
05/12/2025 16:15
Modified
10/12/2025 16:08
Author
Creator
CVSS
8.9 HIGH (v3) 8.9 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
python / urllib3 cpe:2.3:a:python:urllib3:*:*:*:*:*:*:*:*

References