Loop with Unreachable Exit Condition ('Infinite Loop') Affecting request-1276 package, versions <0.30.1-r2


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.29% (20th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CHAINGUARDLATEST-REQUEST1276-20411501
  • published3 Oct 2026
  • disclosed29 Sept 2026

Introduced: 29 Sep 2026

NewCVE-2026-97688  (opens in a new tab)
CWE-835  (opens in a new tab)

How to fix?

Upgrade Chainguard request-1276 to version 0.30.1-r2 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream request-1276 package and not the request-1276 package as distributed by Chainguard. See How to fix? for Chainguard relevant fixed versions and status.

urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the Deflate decoder retains trailing bytes as unconsumed input after reaching end-of-stream and repeatedly decodes them without progress. The issue occurs when an untrusted server sends a chunked Deflate response whose decoded body exceeds a positive finite chunk size and whose encoded body has trailing bytes, specifically a response with Transfer-Encoding: chunked and Content-Encoding: deflate, content decoding enabled, and the positive finite amt=N streaming chunk size. The attack mechanism is that a malicious server returns a compressed chunked response with trailing bytes after the Deflate stream. The impact is excessive CPU usage and a request that does not complete, and network read timeouts do not interrupt the loop because no further socket read occurs. This issue is fixed in version 2.8.0.

CVSS Base Scores

version 3.1