PackageVersionRelated CVEs
python-urllib3
1.24.1-1+deb10u5 (buster)
CVE-2026-21441

It was discovered that python-urllib3, an HTTP library with thread-safe connection pooling for Python, was reading the entire response body to drain the connection and unnecessarily decompressed the content when following HTTP redirects via the streaming API.

This decompression occured in way that bypassed the library’s decompression-bomb safeguards. A malicious server could therefore exploit this behavior to trigger denial of service on the client due to excessive resource consumption (high CPU usage and large memory allocations).

For Debian 10 buster, these problems have b…

Similar Posts

Loading similar posts...

Keyboard Shortcuts

Navigation
Next / previous item
j/k
Open post
oorEnter
Preview post
v
Post Actions
Love post
a
Like post
l
Dislike post
d
Undo reaction
u
Recommendations
Add interest / feed
Enter
Not interested
x
Go to
Home
gh
Interests
gi
Feeds
gf
Likes
gl
History
gy
Changelog
gc
Settings
gs
Browse
gb
Search
/
General
Show this help
?
Submit feedback
!
Close modal / unfocus
Esc

Press ? anytime to show this help