CVE-2025-66471Patch(python / urllib3)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch python urllib3 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. When streaming a compressed response, urllib3 can perform decoding or decompression based on the HTTP Content-Encoding header (e.g., gzip, deflate, br, or zstd). The library must read compressed data from the network and decompress it until the requested chunk size is met. Any resulting decompressed data that exceeds the requested amount is held in an internal buffer for the next read operation. The decompression logic could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This can result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-409

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • urllib3

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-27); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
urllib3

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-27: 2Mentions · 2026-05-29: 1Patch / Workaround · 2026-02-27: 1Patch / Workaround · 2026-05-29: 1Technical Details · 2026-02-27: 1Technical Details · 2026-05-29: 102-2705-29
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-272
Disclosure1Patch1
2026-05-291
Patch1
Full discourse3 posts
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Ubuntu reverts pip patch for CVE-2025-66471 on 22.04, 24.04, 26.04 LTS after regression exposing TLS cert verification flaw CVE-2024-35195 and urllib3 DoS bugs. https://threatcluster.io/cluster/pip-vulnerabilities-lead-to-regression-and-potential-attacks-34f9988e

    Post summary

    Ubuntu reverted the pip patch for CVE-2025-66471 on LTS releases after a regression that revealed the TLS certificate verification flaw CVE-2024-35195 and urllib3 DoS bugs, underscoring the risk of patch misconfiguration.

    0000071
    282 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    🛡️ #DevOps Alert! Two new vulnerabilities (CVE-2025-66418 & CVE-2025-66471) in python-urllib3 are putting #SUSE Linux Micro 6.1 systems at risk. Read mroe: 👉 https://tinyurl.com/42vk9d2e #Security https://t.co/WvJEFtGpJV

    Post summary

    The tweet alerts that two new CVEs (CVE‑2025‑66418 and CVE‑2025‑66471) affect SUSE Linux Micro 6.1, directing readers to read more via a link.

    0000059
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Urgent: #openSUSE Leap 16.0 security update for python-urllib3 fixes 3 DoS flaws (CVE-2025-66471, CVE-2025-66418, CVE-2026-21441). Read more: 👉 https://tinyurl.com/2864pphy #Security #Linux https://t.co/q4gKPJWZxz

    Post summary

    The tweet announces an urgent security update for openSUSE Leap 16.0 that fixes three DoS vulnerabilities in python-urllib3 and directs readers to a link for more details.

    0000057
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppythonurllib3---

Explore more