Pdfly: urllib3: Chunked Deflate streaming can enter an infinite loop (CVE-2026-97688)
urllib3 versions 2.6.2 through 2.7.0 have a vulnerability in their streaming API when handling HTTP responses with chunked Transfer-Encoding and deflate Content-Encoding. Under certain conditions, the decompression process can enter an infinite loop due to trailing bytes after the end of the Deflate stream, causing excessive CPU usage and preventing request completion.
AI Analysis
Technical Summary
The urllib3 library's streaming API can enter an infinite loop when processing chunked HTTP responses that are compressed with Deflate encoding. This occurs if the decompressed body exceeds the requested chunk size and the encoded body contains trailing bytes after the end of the Deflate stream. Python's zlib retains these trailing bytes as unconsumed input, causing urllib3 to repeatedly attempt to decode the same bytes without progress or additional network reads. This flaw affects urllib3 versions from 2.6.2 through 2.7.0 and can be exploited by a malicious server to cause a denial of service via excessive CPU consumption.
Potential Impact
A malicious server can exploit this vulnerability to cause a client using affected urllib3 versions to enter an infinite loop during response decompression, leading to excessive CPU usage and stalled requests. Network timeouts do not interrupt this loop, potentially causing denial of service conditions in applications relying on urllib3 for HTTP streaming with deflate-encoded chunked responses.
Mitigation Recommendations
An official fix is available in urllib3 version 2.8.0, which correctly stops the Deflate decoder from accepting input after the end of the compressed stream. Users should upgrade to urllib3 2.8.0 or later. If immediate upgrade is not possible, disable automatic content decoding for responses from untrusted sources by setting decode_content=False or reject streamed responses using Deflate content encoding. Applications disabling automatic decoding must handle compressed responses safely at another layer.
Pdfly: urllib3: Chunked Deflate streaming can enter an infinite loop (CVE-2026-97688)
Description
urllib3 versions 2.6.2 through 2.7.0 have a vulnerability in their streaming API when handling HTTP responses with chunked Transfer-Encoding and deflate Content-Encoding. Under certain conditions, the decompression process can enter an infinite loop due to trailing bytes after the end of the Deflate stream, causing excessive CPU usage and preventing request completion.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The urllib3 library's streaming API can enter an infinite loop when processing chunked HTTP responses that are compressed with Deflate encoding. This occurs if the decompressed body exceeds the requested chunk size and the encoded body contains trailing bytes after the end of the Deflate stream. Python's zlib retains these trailing bytes as unconsumed input, causing urllib3 to repeatedly attempt to decode the same bytes without progress or additional network reads. This flaw affects urllib3 versions from 2.6.2 through 2.7.0 and can be exploited by a malicious server to cause a denial of service via excessive CPU consumption.
Potential Impact
A malicious server can exploit this vulnerability to cause a client using affected urllib3 versions to enter an infinite loop during response decompression, leading to excessive CPU usage and stalled requests. Network timeouts do not interrupt this loop, potentially causing denial of service conditions in applications relying on urllib3 for HTTP streaming with deflate-encoded chunked responses.
Mitigation Recommendations
An official fix is available in urllib3 version 2.8.0, which correctly stops the Deflate decoder from accepting input after the end of the compressed stream. Users should upgrade to urllib3 2.8.0 or later. If immediate upgrade is not possible, disable automatic content decoding for responses from untrusted sources by setting decode_content=False or reject streamed responses using Deflate content encoding. Applications disabling automatic decoding must handle compressed responses safely at another layer.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-pdfly-CVE-2026-97688
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 4.0
Threat ID: 6ac1396aa43b0b3b89d5fbd3
Added to database: 10/03/2026, 17:20:42 UTC
Last enriched: 10/03/2026, 17:33:26 UTC
Last updated: 10/04/2026, 02:46:08 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.