CVE-2026-44432Patch(python / urllib3)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch python urllib3 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or (2) when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially (compression algorithm did not matter here). These issues could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This could result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data) on the client side. This vulnerability is fixed in 2.7.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-409

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • urllib3

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
urllib3

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-01: 1Patch / Workaround · 2026-07-01: 1Technical Details · 2026-07-01: 107-01
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 Administradores Rocky Linux 8: RLSA-2026:32992 corrige duas vulnerabilidades críticas no python3.12-urllib3: vazamento de headers sensíveis (CVE-2026-44431) e DoS por amplificação de descompressão (CVE-2026-44432). Saiba mais: -> https://tinyurl.com/yc8aeujn #RockyLinux https://t.co/H8dYrffZDe

    Post summary

    The tweet announces the Rocky Linux 8 security advisory RLSA‑2026:32992, which addresses two CVEs affecting python3.12‑urllib3: a sensitive header leak (CVE‑2026‑44431) and a decompression‑amplification DoS (CVE‑2026‑44432), and links to the advisory for patch details.

    0000050
    1.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppythonurllib3---

Explore more