Bug 2419467 (CVE-2025-66471) - CVE-2025-66471 urllib3: urllib3 Streaming API improperly handles highly compressed data
Summary: CVE-2025-66471 urllib3: urllib3 Streaming API improperly handles highly compr...
Keywords:
Status: NEW
Alias: CVE-2025-66471
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2431300 2422221 2422222 2422224 2422225 2427771 2427773 2427774 2427775 2427776 2427777 2427778 2427779 2427780 2427781 2431298 2431299 2431302 2431303
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-12-05 17:02 UTC by OSIDB Bzimport
Modified: 2026-03-05 19:08 UTC (History)
169 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2026:1301 0 None None None 2026-01-26 23:37:41 UTC
Red Hat Product Errata RHBA-2026:1728 0 None None None 2026-02-02 17:00:22 UTC
Red Hat Product Errata RHSA-2026:1086 0 None None None 2026-01-26 12:38:33 UTC
Red Hat Product Errata RHSA-2026:1087 0 None None None 2026-01-26 12:59:46 UTC
Red Hat Product Errata RHSA-2026:1088 0 None None None 2026-01-26 14:14:59 UTC
Red Hat Product Errata RHSA-2026:1089 0 None None None 2026-01-26 14:06:37 UTC
Red Hat Product Errata RHSA-2026:1224 0 None None None 2026-01-26 14:58:13 UTC
Red Hat Product Errata RHSA-2026:1226 0 None None None 2026-01-26 15:29:45 UTC
Red Hat Product Errata RHSA-2026:1239 0 None None None 2026-01-26 17:59:30 UTC
Red Hat Product Errata RHSA-2026:1240 0 None None None 2026-01-26 18:14:10 UTC
Red Hat Product Errata RHSA-2026:1241 0 None None None 2026-01-26 17:55:08 UTC
Red Hat Product Errata RHSA-2026:1249 0 None None None 2026-01-26 19:36:21 UTC
Red Hat Product Errata RHSA-2026:1254 0 None None None 2026-01-26 20:44:30 UTC
Red Hat Product Errata RHSA-2026:1485 0 None None None 2026-01-28 11:22:02 UTC
Red Hat Product Errata RHSA-2026:1497 0 None None None 2026-01-28 15:23:47 UTC
Red Hat Product Errata RHSA-2026:1506 0 None None None 2026-01-28 17:23:18 UTC
Red Hat Product Errata RHSA-2026:1546 0 None None None 2026-01-29 09:08:50 UTC
Red Hat Product Errata RHSA-2026:1618 0 None None None 2026-02-02 01:12:54 UTC
Red Hat Product Errata RHSA-2026:1619 0 None None None 2026-02-02 01:53:23 UTC
Red Hat Product Errata RHSA-2026:1674 0 None None None 2026-02-02 06:38:24 UTC
Red Hat Product Errata RHSA-2026:1676 0 None None None 2026-02-02 06:49:39 UTC
Red Hat Product Errata RHSA-2026:1693 0 None None None 2026-02-02 09:57:11 UTC
Red Hat Product Errata RHSA-2026:1704 0 None None None 2026-02-02 11:45:28 UTC
Red Hat Product Errata RHSA-2026:1706 0 None None None 2026-02-02 12:28:18 UTC
Red Hat Product Errata RHSA-2026:1712 0 None None None 2026-02-02 13:06:01 UTC
Red Hat Product Errata RHSA-2026:1717 0 None None None 2026-02-02 14:02:09 UTC
Red Hat Product Errata RHSA-2026:1726 0 None None None 2026-02-02 15:19:03 UTC
Red Hat Product Errata RHSA-2026:1729 0 None None None 2026-02-02 15:38:36 UTC
Red Hat Product Errata RHSA-2026:1734 0 None None None 2026-02-02 17:37:58 UTC
Red Hat Product Errata RHSA-2026:1735 0 None None None 2026-02-02 17:41:51 UTC
Red Hat Product Errata RHSA-2026:1791 0 None None None 2026-02-03 07:14:52 UTC
Red Hat Product Errata RHSA-2026:1792 0 None None None 2026-02-03 07:16:57 UTC
Red Hat Product Errata RHSA-2026:1793 0 None None None 2026-02-03 07:14:17 UTC
Red Hat Product Errata RHSA-2026:1794 0 None None None 2026-02-03 07:15:19 UTC
Red Hat Product Errata RHSA-2026:1795 0 None None None 2026-02-03 07:24:47 UTC
Red Hat Product Errata RHSA-2026:1803 0 None None None 2026-02-03 09:41:07 UTC
Red Hat Product Errata RHSA-2026:1805 0 None None None 2026-02-03 10:15:12 UTC
Red Hat Product Errata RHSA-2026:1957 0 None None None 2026-02-04 19:11:35 UTC
Red Hat Product Errata RHSA-2026:2060 0 None None None 2026-02-05 09:40:30 UTC
Red Hat Product Errata RHSA-2026:2717 0 None None None 2026-02-16 11:27:09 UTC
Red Hat Product Errata RHSA-2026:2718 0 None None None 2026-02-16 11:36:09 UTC
Red Hat Product Errata RHSA-2026:2723 0 None None None 2026-02-16 11:23:45 UTC
Red Hat Product Errata RHSA-2026:2728 0 None None None 2026-02-16 11:54:04 UTC
Red Hat Product Errata RHSA-2026:2760 0 None None None 2026-02-16 16:48:27 UTC
Red Hat Product Errata RHSA-2026:2764 0 None None None 2026-02-16 19:02:58 UTC
Red Hat Product Errata RHSA-2026:2765 0 None None None 2026-02-16 21:29:59 UTC

Description OSIDB Bzimport 2025-12-05 17:02:45 UTC
urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. When streaming a compressed response, urllib3 can perform decoding or decompression based on the HTTP Content-Encoding header (e.g., gzip, deflate, br, or zstd). The library must read compressed data from the network and decompress it until the requested chunk size is met. Any resulting decompressed data that exceeds the requested amount is held in an internal buffer for the next read operation. The decompression logic could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This can result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data.

Comment 2 errata-xmlrpc 2026-01-26 12:38:22 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:1086 https://access.redhat.com/errata/RHSA-2026:1086

Comment 3 errata-xmlrpc 2026-01-26 12:59:33 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:1087 https://access.redhat.com/errata/RHSA-2026:1087

Comment 4 errata-xmlrpc 2026-01-26 14:06:26 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:1089 https://access.redhat.com/errata/RHSA-2026:1089

Comment 5 errata-xmlrpc 2026-01-26 14:14:47 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:1088 https://access.redhat.com/errata/RHSA-2026:1088

Comment 6 errata-xmlrpc 2026-01-26 14:58:01 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:1224 https://access.redhat.com/errata/RHSA-2026:1224

Comment 7 errata-xmlrpc 2026-01-26 15:29:35 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:1226 https://access.redhat.com/errata/RHSA-2026:1226

Comment 8 errata-xmlrpc 2026-01-26 17:54:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:1241 https://access.redhat.com/errata/RHSA-2026:1241

Comment 9 errata-xmlrpc 2026-01-26 17:59:18 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:1239 https://access.redhat.com/errata/RHSA-2026:1239

Comment 10 errata-xmlrpc 2026-01-26 18:13:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:1240 https://access.redhat.com/errata/RHSA-2026:1240

Comment 11 errata-xmlrpc 2026-01-26 19:36:10 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.6 for RHEL 9
  Red Hat Ansible Automation Platform 2.6 for RHEL 10

Via RHSA-2026:1249 https://access.redhat.com/errata/RHSA-2026:1249

Comment 12 errata-xmlrpc 2026-01-26 20:44:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:1254 https://access.redhat.com/errata/RHSA-2026:1254

Comment 13 errata-xmlrpc 2026-01-28 11:21:51 UTC
This issue has been addressed in the following products:

  RHUI 4 for RHEL 8

Via RHSA-2026:1485 https://access.redhat.com/errata/RHSA-2026:1485

Comment 14 errata-xmlrpc 2026-01-28 15:23:37 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.4 for RHEL 8
  Red Hat Ansible Automation Platform 2.4 for RHEL 9

Via RHSA-2026:1497 https://access.redhat.com/errata/RHSA-2026:1497

Comment 15 errata-xmlrpc 2026-01-28 17:23:07 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.5 for RHEL 9
  Red Hat Ansible Automation Platform 2.5 for RHEL 8

Via RHSA-2026:1506 https://access.redhat.com/errata/RHSA-2026:1506

Comment 16 errata-xmlrpc 2026-01-29 09:08:38 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:1546 https://access.redhat.com/errata/RHSA-2026:1546

Comment 17 errata-xmlrpc 2026-02-02 01:12:42 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2026:1618 https://access.redhat.com/errata/RHSA-2026:1618

Comment 18 errata-xmlrpc 2026-02-02 01:53:11 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:1619 https://access.redhat.com/errata/RHSA-2026:1619

Comment 19 errata-xmlrpc 2026-02-02 06:38:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2026:1674 https://access.redhat.com/errata/RHSA-2026:1674

Comment 20 errata-xmlrpc 2026-02-02 06:49:27 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:1676 https://access.redhat.com/errata/RHSA-2026:1676

Comment 21 errata-xmlrpc 2026-02-02 09:56:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:1693 https://access.redhat.com/errata/RHSA-2026:1693

Comment 22 errata-xmlrpc 2026-02-02 11:45:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:1704 https://access.redhat.com/errata/RHSA-2026:1704

Comment 23 errata-xmlrpc 2026-02-02 12:28:06 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:1706 https://access.redhat.com/errata/RHSA-2026:1706

Comment 24 errata-xmlrpc 2026-02-02 13:05:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2026:1712 https://access.redhat.com/errata/RHSA-2026:1712

Comment 25 errata-xmlrpc 2026-02-02 14:01:58 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2026:1717 https://access.redhat.com/errata/RHSA-2026:1717

Comment 26 errata-xmlrpc 2026-02-02 15:18:51 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:1726 https://access.redhat.com/errata/RHSA-2026:1726

Comment 27 errata-xmlrpc 2026-02-02 15:38:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:1729 https://access.redhat.com/errata/RHSA-2026:1729

Comment 28 errata-xmlrpc 2026-02-02 17:37:47 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2026:1734 https://access.redhat.com/errata/RHSA-2026:1734

Comment 29 errata-xmlrpc 2026-02-02 17:41:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:1735 https://access.redhat.com/errata/RHSA-2026:1735

Comment 30 errata-xmlrpc 2026-02-03 07:14:05 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2026:1793 https://access.redhat.com/errata/RHSA-2026:1793

Comment 31 errata-xmlrpc 2026-02-03 07:14:41 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:1791 https://access.redhat.com/errata/RHSA-2026:1791

Comment 32 errata-xmlrpc 2026-02-03 07:15:08 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:1794 https://access.redhat.com/errata/RHSA-2026:1794

Comment 33 errata-xmlrpc 2026-02-03 07:16:46 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2026:1792 https://access.redhat.com/errata/RHSA-2026:1792

Comment 34 errata-xmlrpc 2026-02-03 07:24:35 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2026:1795 https://access.redhat.com/errata/RHSA-2026:1795

Comment 35 errata-xmlrpc 2026-02-03 09:40:56 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:1803 https://access.redhat.com/errata/RHSA-2026:1803

Comment 36 errata-xmlrpc 2026-02-03 10:15:01 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:1805 https://access.redhat.com/errata/RHSA-2026:1805

Comment 37 errata-xmlrpc 2026-02-04 19:11:23 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2026:1957 https://access.redhat.com/errata/RHSA-2026:1957

Comment 38 errata-xmlrpc 2026-02-05 09:40:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2026:2060 https://access.redhat.com/errata/RHSA-2026:2060

Comment 40 errata-xmlrpc 2026-02-16 11:23:34 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:2723 https://access.redhat.com/errata/RHSA-2026:2723

Comment 41 errata-xmlrpc 2026-02-16 11:26:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2026:2717 https://access.redhat.com/errata/RHSA-2026:2717

Comment 42 errata-xmlrpc 2026-02-16 11:35:59 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:2718 https://access.redhat.com/errata/RHSA-2026:2718

Comment 43 errata-xmlrpc 2026-02-16 11:53:53 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Advanced Update Support

Via RHSA-2026:2728 https://access.redhat.com/errata/RHSA-2026:2728

Comment 44 errata-xmlrpc 2026-02-16 16:48:16 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.18 for RHEL 9

Via RHSA-2026:2760 https://access.redhat.com/errata/RHSA-2026:2760

Comment 45 errata-xmlrpc 2026-02-16 19:02:48 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.17 for RHEL 9

Via RHSA-2026:2764 https://access.redhat.com/errata/RHSA-2026:2764

Comment 46 errata-xmlrpc 2026-02-16 21:29:47 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.16 for RHEL 8
  Red Hat Satellite 6.16 for RHEL 9

Via RHSA-2026:2765 https://access.redhat.com/errata/RHSA-2026:2765


Note You need to log in before you can comment on or make changes to this bug.