Allocation of Resources Without Limits or Throttling Affecting urllib3 package, versions [1.10.3,2.8.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.29% (20th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-URLLIB3-20302846
  • published30 Sept 2026
  • disclosed29 Sept 2026
  • creditQuentin Pradet, Illia Volochii

Introduced: 29 Sep 2026

NewCVE-2026-97689  (opens in a new tab)
CWE-770  (opens in a new tab)

How to fix?

Upgrade urllib3 to version 2.8.0 or higher.

Overview

urllib3 is a HTTP library with thread-safe connection pooling, file post, and more.

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via HTTPResponse._update_chunk_length() in response.py, where the chunk-size line in a chunked transfer-encoded response is read with an unbounded readline() call. A malicious server can send a Transfer-Encoding: chunked response followed by an unterminated chunk-size line of arbitrary length, forcing the client to buffer the entire run in memory before the read can be rejected, causing memory exhaustion.

Note: This is only exploitable when the client connects to a malicious or compromised server, and applies only to the chunk-size line read, not to chunk body data.

CVSS Base Scores

version 4.0
version 3.1