Bug 2419467 (CVE-2025-66471) - CVE-2025-66471 urllib3: urllib3 Streaming API improperly handles highly compressed data
Summary: CVE-2025-66471 urllib3: urllib3 Streaming API improperly handles highly compr...
Keywords:
Status: NEW
Alias: CVE-2025-66471
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2422221 2422222 2422224 2431299 2431300 2431302 2422225 2427771 2427773 2427774 2427775 2427776 2427777 2427778 2427779 2427780 2427781 2431298 2431303
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-12-05 17:02 UTC by OSIDB Bzimport
Modified: 2026-01-26 23:37 UTC (History)
166 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2026:1301 0 None None None 2026-01-26 23:37:41 UTC
Red Hat Product Errata RHSA-2026:1086 0 None None None 2026-01-26 12:38:33 UTC
Red Hat Product Errata RHSA-2026:1087 0 None None None 2026-01-26 12:59:46 UTC
Red Hat Product Errata RHSA-2026:1088 0 None None None 2026-01-26 14:14:59 UTC
Red Hat Product Errata RHSA-2026:1089 0 None None None 2026-01-26 14:06:37 UTC
Red Hat Product Errata RHSA-2026:1224 0 None None None 2026-01-26 14:58:13 UTC
Red Hat Product Errata RHSA-2026:1226 0 None None None 2026-01-26 15:29:45 UTC
Red Hat Product Errata RHSA-2026:1239 0 None None None 2026-01-26 17:59:30 UTC
Red Hat Product Errata RHSA-2026:1240 0 None None None 2026-01-26 18:14:10 UTC
Red Hat Product Errata RHSA-2026:1241 0 None None None 2026-01-26 17:55:08 UTC
Red Hat Product Errata RHSA-2026:1249 0 None None None 2026-01-26 19:36:21 UTC
Red Hat Product Errata RHSA-2026:1254 0 None None None 2026-01-26 20:44:30 UTC

Description OSIDB Bzimport 2025-12-05 17:02:45 UTC
urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. When streaming a compressed response, urllib3 can perform decoding or decompression based on the HTTP Content-Encoding header (e.g., gzip, deflate, br, or zstd). The library must read compressed data from the network and decompress it until the requested chunk size is met. Any resulting decompressed data that exceeds the requested amount is held in an internal buffer for the next read operation. The decompression logic could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This can result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data.

Comment 2 errata-xmlrpc 2026-01-26 12:38:22 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:1086 https://access.redhat.com/errata/RHSA-2026:1086

Comment 3 errata-xmlrpc 2026-01-26 12:59:33 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:1087 https://access.redhat.com/errata/RHSA-2026:1087

Comment 4 errata-xmlrpc 2026-01-26 14:06:26 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:1089 https://access.redhat.com/errata/RHSA-2026:1089

Comment 5 errata-xmlrpc 2026-01-26 14:14:47 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:1088 https://access.redhat.com/errata/RHSA-2026:1088

Comment 6 errata-xmlrpc 2026-01-26 14:58:01 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:1224 https://access.redhat.com/errata/RHSA-2026:1224

Comment 7 errata-xmlrpc 2026-01-26 15:29:35 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:1226 https://access.redhat.com/errata/RHSA-2026:1226

Comment 8 errata-xmlrpc 2026-01-26 17:54:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:1241 https://access.redhat.com/errata/RHSA-2026:1241

Comment 9 errata-xmlrpc 2026-01-26 17:59:18 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:1239 https://access.redhat.com/errata/RHSA-2026:1239

Comment 10 errata-xmlrpc 2026-01-26 18:13:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:1240 https://access.redhat.com/errata/RHSA-2026:1240

Comment 11 errata-xmlrpc 2026-01-26 19:36:10 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.6 for RHEL 9
  Red Hat Ansible Automation Platform 2.6 for RHEL 10

Via RHSA-2026:1249 https://access.redhat.com/errata/RHSA-2026:1249

Comment 12 errata-xmlrpc 2026-01-26 20:44:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:1254 https://access.redhat.com/errata/RHSA-2026:1254


Note You need to log in before you can comment on or make changes to this bug.