← Vulnerability feed

Vulnerability record · CVE-2026-44432 · published 13 May 2026

CVE-2026-44432: Python urllib3 vulnerability

Python · Urllib3

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0.

8.9 CVSS 4.0 High EPSS 0.88% · top 42.5% CWE-409 · CWE-409
8.9CVSS 4.0 base score
0.88%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
62References
10 Sep 2026Last modified by NVD

Description

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0.

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j MitigationVendor Advisory
https://access.redhat.com/errata/RHSA-2026:15862
https://access.redhat.com/errata/RHSA-2026:20338
https://access.redhat.com/errata/RHSA-2026:22934
https://access.redhat.com/errata/RHSA-2026:24000
https://access.redhat.com/errata/RHSA-2026:24009
https://access.redhat.com/errata/RHSA-2026:24014
https://access.redhat.com/errata/RHSA-2026:24069
https://access.redhat.com/errata/RHSA-2026:24374
https://access.redhat.com/errata/RHSA-2026:24476
https://access.redhat.com/errata/RHSA-2026:24483
https://access.redhat.com/errata/RHSA-2026:24540
https://access.redhat.com/errata/RHSA-2026:24541
https://access.redhat.com/errata/RHSA-2026:24542
https://access.redhat.com/errata/RHSA-2026:24544
https://access.redhat.com/errata/RHSA-2026:25039
https://access.redhat.com/errata/RHSA-2026:25143
https://access.redhat.com/errata/RHSA-2026:25928
https://access.redhat.com/errata/RHSA-2026:26212
https://access.redhat.com/errata/RHSA-2026:26304
https://access.redhat.com/errata/RHSA-2026:27929
https://access.redhat.com/errata/RHSA-2026:28000
https://access.redhat.com/errata/RHSA-2026:28157
https://access.redhat.com/errata/RHSA-2026:28158
https://access.redhat.com/errata/RHSA-2026:28159
https://access.redhat.com/errata/RHSA-2026:28571
https://access.redhat.com/errata/RHSA-2026:30076
https://access.redhat.com/errata/RHSA-2026:30078
https://access.redhat.com/errata/RHSA-2026:30087
https://access.redhat.com/errata/RHSA-2026:30088
https://access.redhat.com/errata/RHSA-2026:30089
https://access.redhat.com/errata/RHSA-2026:32992
https://access.redhat.com/errata/RHSA-2026:33313
https://access.redhat.com/errata/RHSA-2026:33683
https://access.redhat.com/errata/RHSA-2026:34160
https://access.redhat.com/errata/RHSA-2026:34374
https://access.redhat.com/errata/RHSA-2026:34526
https://access.redhat.com/errata/RHSA-2026:34531
https://access.redhat.com/errata/RHSA-2026:34533
https://access.redhat.com/errata/RHSA-2026:34607

Track CVE-2026-44432 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-20060Python urllib3 vulnerabilityurllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in ho…EPSS 4.5%8.9CVE-2026-21441Python urllib3 vulnerabilityurllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the c…EPSS 3.0%8.9CVE-2025-66471Python urllib3 vulnerabilityurllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly co…EPSS 0.68%8.9CVE-2025-66418Python urllib3 allocation without limits vulnerabilityurllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chai…EPSS 0.68%8.2CVE-2026-44431Python urllib3 information exposure vulnerabilityurllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.conn…EPSS 0.34%8.1CVE-2023-43804Python urllib3 information exposure vulnerabilityurllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing…EPSS 1.2%7.5CVE-2021-33503Python urllib3 uncontrolled resource consumption vulnerabilityAn issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority reg…EPSS 3.3%7.5CVE-2020-7212Python urllib3 uncontrolled resource consumption vulnerabilityThe _encode_invalid_chars function in util/url.py in the urllib3 library 1.25.2 through 1.25.7 for Python allows a denial of service (CPU consumption…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2026-44432), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.