CVE-2026-59939PoC(httplib2_project / httplib2)

HIGHCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch httplib2_project httplib2 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allowing a malicious or compromised HTTP server to return a small compressed payload that expands to an arbitrarily large size in memory and causes MemoryError or OOM-kill in the client process. This issue is fixed in version 0.32.0.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-409

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • httplib2

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 2 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Peaked 1d ago at 3 mentions (2026-07-09); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Products
httplib2

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-07-09: 3Mentions · 2026-07-13: 2PoC Mentioned / Linked · 2026-07-09: 2PoC Mentioned / Linked · 2026-07-13: 1Exploit Tool / Code · 2026-07-09: 1Active Exploitation · 2026-07-13: 1Patch / Workaround · 2026-07-09: 1Technical Details · 2026-07-09: 3Technical Details · 2026-07-13: 107-0907-13
Signal classification4 categories
PoC
240.0%
Patch
120.0%
Active Exploitation
120.0%
Disclosure
120.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-093
Patch1PoC2
2026-07-132
Active Exploitation1Disclosure1
Full discourse5 posts
  • CSIRT Italia@csirt_it
    PoC

    #PoC pubblico per lo sfruttamento della vulnerabilità CVE-2026-53359 che interessa la libreria Httplib2 di python Rischio: 🔴 Tipologia: 🔸 Denial of Service 🔗 https://www.acn.gov.it/portale/w/httplib2-poc-pubblico-per-lo-sfruttamento-della-cve-2026-59939 🔄 Aggiornamenti disponibili 🔄 https://t.co/hVBusY2We2

    Post summary

    The tweet announces a public Proof‑of‑Concept for CVE‑2026‑53359, a denial‑of‑service vulnerability in Python’s httplib2, and provides a link to the PoC code.

    00040639
    9.1K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔵 httplib2 Unbounded Decompression Denial of Service Vulnerability #CVE-2026-59939 (Low) -DC-Jul2026-908 https://dailycve.com/httplib2-unbounded-decompression-denial-of-service-vulnerability-cve-2026-59939-low-dc-jul2026-908/

    Post summary

    The post announces the discovery of CVE‑2026‑59939, an unbounded decompression DoS vulnerability in httplib2, without providing PoC, exploit details, active exploitation evidence, or patch information.

    0000040
    218 followersView on X
  • Hephaestvs@Vulcanux_
    Active Exploitation

    csirt_it: La Settimana Cibernetica del 12 luglio 2026 🔹aggiornamenti per molteplici prodotti 🔹 Langflow: rilevato lo sfruttamento in rete della CVE-2026-55255 🔹 Httplib2: PoC pubblico per lo sfruttamento della CVE-2026-59939 ⚠️#EPSS 🔗 … https://t.co/6pYEwcABF3

    Post summary

    The tweet reports active exploitation of CVE-2026-55255 on Langflow and a public PoC for CVE-2026-59939 on httplib2, without any patch or mitigation details provided.

    0000044
    625 followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: #PoC pubblico per lo sfruttamento della vulnerabilità CVE-2026-53359 che interessa la libreria Httplib2 di python Rischio: 🔴 Tipologia: 🔸 Denial of Service 🔗 https://www.acn.gov.it/portale/w/httplib2-poc-pubblico-per-lo-sfruttamento-della-cve-2026-59939 🔄 Aggiornamenti disponibili 🔄 https://t.co/nV38OgPlT8

    Post summary

    A tweet announces a publicly available PoC that exploits CVE-2026-53359 to cause a DoS in the Python library httplib2, linking to the code repository.

    0000052
    625 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 HIGH - Unbounded gzip/deflate decompression in httplib2 HTTP client (CVE-2026-59939) CVE-2026-59939 is a denial-of-service flaw in the httplib2 Python HTTP client, specifically in the _decompressContent handling of gzip/deflate-encoded response bodies. The root cause is missing bounds/limits during decompression (uncontrolled resource consumption / decompression bomb). An attacker can exploit this by operating a malicious or compromised HTTP server (or MITM’ing traffic) that returns a tiny compressed response which expands massively when the client auto-decompresses it, with no special client-side privileges required beyond making the request. Impact is process memory exhaustion leading to MemoryError, client crashes, or the host/container being OOM-killed, potentially taking down dependent services. 👉 Affected: httplib2 < 0.32.0 | Upgrade to 0.32.0

    Post summary

    The advisory discloses a DOS flaw in httplib2’s decompression handler and recommends upgrading to version 0.32.0 to mitigate the risk.

    00000112
    246 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphttplib2_projecthttplib2-python-

Explore more