CVE-2025-66418Disclosure(python / urllib3)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch python urllib3 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • urllib3

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
urllib3

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-27: 2Patch / Workaround · 2026-02-27: 1Technical Details · 2026-02-27: 102-27
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    🛡️ #DevOps Alert! Two new vulnerabilities (CVE-2025-66418 & CVE-2025-66471) in python-urllib3 are putting #SUSE Linux Micro 6.1 systems at risk. Read mroe: 👉 https://tinyurl.com/42vk9d2e #Security https://t.co/WvJEFtGpJV

    Post summary

    The tweet announces two new CVEs (CVE-2025-66418 & CVE-2025-66471) in python-urllib3 that pose a risk to SUSE Linux Micro 6.1 systems, directing readers to a link for additional details.

    0000059
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Urgent: #openSUSE Leap 16.0 security update for python-urllib3 fixes 3 DoS flaws (CVE-2025-66471, CVE-2025-66418, CVE-2026-21441). Read more: 👉 https://tinyurl.com/2864pphy #Security #Linux https://t.co/q4gKPJWZxz

    Post summary

    openSUSE Leap 16.0 receives a security update that fixes three DoS vulnerabilities in python‑urllib3; no proof‑of‑concept or evidence of active exploitation is reported.

    0000057
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppythonurllib3---

Explore more