urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. When streaming a compressed response, urllib3 can perform decoding or decompression based on the HTTP Content-Encoding header (e.g., gzip, deflate, br, or zstd). The library must read compressed data from the network and decompress it until the requested chunk size is met. Any resulting decompressed data that exceeds the requested amount is held in an internal buffer for the next read operation. The decompression logic could cause urllib3 to fully decode a small amount of highly compressed data in a single operation. This can result in excessive resource consumption (high CPU usage and massive memory allocation for the decompressed data.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:1086 https://access.redhat.com/errata/RHSA-2026:1086
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:1087 https://access.redhat.com/errata/RHSA-2026:1087
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:1089 https://access.redhat.com/errata/RHSA-2026:1089
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:1088 https://access.redhat.com/errata/RHSA-2026:1088
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:1224 https://access.redhat.com/errata/RHSA-2026:1224
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:1226 https://access.redhat.com/errata/RHSA-2026:1226
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:1241 https://access.redhat.com/errata/RHSA-2026:1241
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:1239 https://access.redhat.com/errata/RHSA-2026:1239
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:1240 https://access.redhat.com/errata/RHSA-2026:1240
This issue has been addressed in the following products: Red Hat Ansible Automation Platform 2.6 for RHEL 9 Red Hat Ansible Automation Platform 2.6 for RHEL 10 Via RHSA-2026:1249 https://access.redhat.com/errata/RHSA-2026:1249
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:1254 https://access.redhat.com/errata/RHSA-2026:1254
This issue has been addressed in the following products: RHUI 4 for RHEL 8 Via RHSA-2026:1485 https://access.redhat.com/errata/RHSA-2026:1485
This issue has been addressed in the following products: Red Hat Ansible Automation Platform 2.4 for RHEL 8 Red Hat Ansible Automation Platform 2.4 for RHEL 9 Via RHSA-2026:1497 https://access.redhat.com/errata/RHSA-2026:1497
This issue has been addressed in the following products: Red Hat Ansible Automation Platform 2.5 for RHEL 9 Red Hat Ansible Automation Platform 2.5 for RHEL 8 Via RHSA-2026:1506 https://access.redhat.com/errata/RHSA-2026:1506
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:1546 https://access.redhat.com/errata/RHSA-2026:1546
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:1618 https://access.redhat.com/errata/RHSA-2026:1618
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:1619 https://access.redhat.com/errata/RHSA-2026:1619
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:1674 https://access.redhat.com/errata/RHSA-2026:1674
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:1676 https://access.redhat.com/errata/RHSA-2026:1676
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:1693 https://access.redhat.com/errata/RHSA-2026:1693
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:1704 https://access.redhat.com/errata/RHSA-2026:1704
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:1706 https://access.redhat.com/errata/RHSA-2026:1706
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:1712 https://access.redhat.com/errata/RHSA-2026:1712
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:1717 https://access.redhat.com/errata/RHSA-2026:1717
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:1726 https://access.redhat.com/errata/RHSA-2026:1726
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:1729 https://access.redhat.com/errata/RHSA-2026:1729
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:1734 https://access.redhat.com/errata/RHSA-2026:1734
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:1735 https://access.redhat.com/errata/RHSA-2026:1735
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:1793 https://access.redhat.com/errata/RHSA-2026:1793
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:1791 https://access.redhat.com/errata/RHSA-2026:1791
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:1794 https://access.redhat.com/errata/RHSA-2026:1794
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:1792 https://access.redhat.com/errata/RHSA-2026:1792
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:1795 https://access.redhat.com/errata/RHSA-2026:1795
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:1803 https://access.redhat.com/errata/RHSA-2026:1803
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:1805 https://access.redhat.com/errata/RHSA-2026:1805
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:1957 https://access.redhat.com/errata/RHSA-2026:1957
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:2060 https://access.redhat.com/errata/RHSA-2026:2060
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:2723 https://access.redhat.com/errata/RHSA-2026:2723
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:2717 https://access.redhat.com/errata/RHSA-2026:2717
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:2718 https://access.redhat.com/errata/RHSA-2026:2718
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2026:2728 https://access.redhat.com/errata/RHSA-2026:2728
This issue has been addressed in the following products: Red Hat Satellite 6.18 for RHEL 9 Via RHSA-2026:2760 https://access.redhat.com/errata/RHSA-2026:2760
This issue has been addressed in the following products: Red Hat Satellite 6.17 for RHEL 9 Via RHSA-2026:2764 https://access.redhat.com/errata/RHSA-2026:2764
This issue has been addressed in the following products: Red Hat Satellite 6.16 for RHEL 8 Red Hat Satellite 6.16 for RHEL 9 Via RHSA-2026:2765 https://access.redhat.com/errata/RHSA-2026:2765