Bug 2427726 (CVE-2026-21441)
| Summary: | CVE-2026-21441 urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | abarbaro, adinn, adistefa, alcohan, alinfoot, alizardo, amctagga, anjoseph, anpicker, anthomas, aoconnor, aprice, bbrownin, bdettelb, bniver, bparees, brasmith, cahl, carogers, caswilli, cmyers, cochase, crizzo, dfreiber, dhanak, dnakabaa, doconnor, dranck, drosa, drow, dschmidt, dsimansk, dtrifiro, dymurray, eborisov, eglynn, ehelms, erezende, flucifre, fzakkak, galder, galder.zamarreno, ggainey, gmeno, gparvin, groman, gtanzill, haoli, hasun, hkataria, ibolton, jajackso, jbalunas, jburrell, jbuscemi, jcammara, jcantril, jchui, jdobes, jfula, jhe, jjoyce, jkoehler, jlanda, jmatthew, jmitchel, jmontleo, jneedle, joehler, jowilson, jpasqual, jprabhak, jpretori, jsamir, jschluet, juwatts, jwong, kaycoth, kbempah, kegrant, kgaikwad, kingland, koliveir, kshier, ktsao, kverlaen, lball, lbrazdil, lchilton, lcouzens, lgamliel, lhh, ljawale, lphiri, luizcosta, mabashia, manissin, mattdavi, matzew, mbabacek, mbenjamin, mburns, mgarciac, mhackett, mhayden, mhess, mhulan, mminar, mnovotny, mrunge, msilmser, mskarbek, nboldt, ngough, nmoumoul, nweather, nyancey, oaljalju, oezr, olubyans, omaciel, ometelka, orabin, osousa, owatkins, pahickey, pakotvan, pbraun, pcreech, pgaikwad, pjindal, prwatson, psrna, ptisnovs, rbiba, rbobbitt, rbryant, rchan, rekumar, rfreiman, rhaigner, rhel-process-autobot, rjohnson, rojacob, sausingh, sbiarozk, sbratsla, sdawley, sdoran, sfeifer, sgehwolf, shvarugh, simaishi, slucidi, smallamp, smcdonal, solenoci, sostapov, sseago, sskracic, stcannon, sthirugn, syedriko, teagle, tfister, thavo, tmalecek, tpfromme, tqvarnst, ttakamiy, tzivkovi, vereddy, veshanka, vimartin, vkumar, vle, vvoronko, vwilson, watson-tool-maintainers, weaton, whayutin, wtam, xdharmai, yguenane, zdohnal, zzhou |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2428642, 2428643, 2428644, 2428645, 2428646, 2428647, 2428648, 2428649, 2428650, 2428651, 2428730, 2428731, 2431305, 2431306, 2431307, 2431309, 2431310 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-01-07 23:02:25 UTC
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:1086 https://access.redhat.com/errata/RHSA-2026:1086 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:1087 https://access.redhat.com/errata/RHSA-2026:1087 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:1089 https://access.redhat.com/errata/RHSA-2026:1089 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:1088 https://access.redhat.com/errata/RHSA-2026:1088 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:1224 https://access.redhat.com/errata/RHSA-2026:1224 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:1226 https://access.redhat.com/errata/RHSA-2026:1226 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:1241 https://access.redhat.com/errata/RHSA-2026:1241 This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:1239 https://access.redhat.com/errata/RHSA-2026:1239 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:1240 https://access.redhat.com/errata/RHSA-2026:1240 This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:1254 https://access.redhat.com/errata/RHSA-2026:1254 This issue has been addressed in the following products: RHUI 4 for RHEL 8 Via RHSA-2026:1485 https://access.redhat.com/errata/RHSA-2026:1485 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:1546 https://access.redhat.com/errata/RHSA-2026:1546 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:1618 https://access.redhat.com/errata/RHSA-2026:1618 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:1619 https://access.redhat.com/errata/RHSA-2026:1619 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:1674 https://access.redhat.com/errata/RHSA-2026:1674 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:1676 https://access.redhat.com/errata/RHSA-2026:1676 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:1693 https://access.redhat.com/errata/RHSA-2026:1693 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:1704 https://access.redhat.com/errata/RHSA-2026:1704 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:1706 https://access.redhat.com/errata/RHSA-2026:1706 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:1712 https://access.redhat.com/errata/RHSA-2026:1712 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:1717 https://access.redhat.com/errata/RHSA-2026:1717 This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:1726 https://access.redhat.com/errata/RHSA-2026:1726 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:1729 https://access.redhat.com/errata/RHSA-2026:1729 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:1734 https://access.redhat.com/errata/RHSA-2026:1734 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:1735 https://access.redhat.com/errata/RHSA-2026:1735 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:1793 https://access.redhat.com/errata/RHSA-2026:1793 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:1791 https://access.redhat.com/errata/RHSA-2026:1791 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:1794 https://access.redhat.com/errata/RHSA-2026:1794 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:1792 https://access.redhat.com/errata/RHSA-2026:1792 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:1803 https://access.redhat.com/errata/RHSA-2026:1803 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:1805 https://access.redhat.com/errata/RHSA-2026:1805 This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:1957 https://access.redhat.com/errata/RHSA-2026:1957 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:2723 https://access.redhat.com/errata/RHSA-2026:2723 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:2717 https://access.redhat.com/errata/RHSA-2026:2717 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:2718 https://access.redhat.com/errata/RHSA-2026:2718 This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2026:2728 https://access.redhat.com/errata/RHSA-2026:2728 This issue has been addressed in the following products: Red Hat Satellite 6.18 for RHEL 9 Via RHSA-2026:2760 https://access.redhat.com/errata/RHSA-2026:2760 This issue has been addressed in the following products: Red Hat Satellite 6.17 for RHEL 9 Via RHSA-2026:2764 https://access.redhat.com/errata/RHSA-2026:2764 This issue has been addressed in the following products: Red Hat Satellite 6.16 for RHEL 8 Red Hat Satellite 6.16 for RHEL 9 Via RHSA-2026:2765 https://access.redhat.com/errata/RHSA-2026:2765 This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:2911 https://access.redhat.com/errata/RHSA-2026:2911 This issue has been addressed in the following products: Red Hat OpenStack Platform 17.1 for RHEL 8 Via RHSA-2026:28043 https://access.redhat.com/errata/RHSA-2026:28043 |