urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. When streaming a compressed response, urllib3 can perform decoding or decompression based on the HTTP Content-Encoding header (e.g., gzip, deflate, br, or zstd). The library must read compressed data from the network and decompress it until the requested chunk size is met. Any resulting decompressed data that exceeds the requested amount is held in an internal buffer for the next read operation. The decompression logic could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This can result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:1086 https://access.redhat.com/errata/RHSA-2026:1086
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:1087 https://access.redhat.com/errata/RHSA-2026:1087
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:1089 https://access.redhat.com/errata/RHSA-2026:1089
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:1088 https://access.redhat.com/errata/RHSA-2026:1088
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:1224 https://access.redhat.com/errata/RHSA-2026:1224
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:1226 https://access.redhat.com/errata/RHSA-2026:1226
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:1241 https://access.redhat.com/errata/RHSA-2026:1241
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:1239 https://access.redhat.com/errata/RHSA-2026:1239
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:1240 https://access.redhat.com/errata/RHSA-2026:1240
This issue has been addressed in the following products: Red Hat Ansible Automation Platform 2.6 for RHEL 9 Red Hat Ansible Automation Platform 2.6 for RHEL 10 Via RHSA-2026:1249 https://access.redhat.com/errata/RHSA-2026:1249
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:1254 https://access.redhat.com/errata/RHSA-2026:1254