Skip to main content
EPSS 0.3%top 80%

Pdfly: urllib3: Chunked Deflate streaming can enter an infinite loop (CVE-2026-97688)

0
High
Published: 09/30/2026 (09/30/2026, 20:28:12 UTC)
Source: GCVE Database
Product: pdfly

Description

urllib3 versions 2.6.2 through 2.7.0 have a vulnerability in their streaming API when handling HTTP responses with chunked Transfer-Encoding and deflate Content-Encoding. Under certain conditions, the decompression process can enter an infinite loop due to trailing bytes after the end of the Deflate stream, causing excessive CPU usage and preventing request completion.

CVSS v4.0

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
None
Vuln. Availability
Low
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected software

Homebrewmore threats →ghsa
pdfly
pkg:brew/pdfly
Affected versions
>=0.5.1_5 <0.5.1_26

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/03/2026, 17:33:26 UTC

Technical Analysis

The urllib3 library's streaming API can enter an infinite loop when processing chunked HTTP responses that are compressed with Deflate encoding. This occurs if the decompressed body exceeds the requested chunk size and the encoded body contains trailing bytes after the end of the Deflate stream. Python's zlib retains these trailing bytes as unconsumed input, causing urllib3 to repeatedly attempt to decode the same bytes without progress or additional network reads. This flaw affects urllib3 versions from 2.6.2 through 2.7.0 and can be exploited by a malicious server to cause a denial of service via excessive CPU consumption.

Potential Impact

A malicious server can exploit this vulnerability to cause a client using affected urllib3 versions to enter an infinite loop during response decompression, leading to excessive CPU usage and stalled requests. Network timeouts do not interrupt this loop, potentially causing denial of service conditions in applications relying on urllib3 for HTTP streaming with deflate-encoded chunked responses.

Mitigation Recommendations

An official fix is available in urllib3 version 2.8.0, which correctly stops the Deflate decoder from accepting input after the end of the compressed stream. Users should upgrade to urllib3 2.8.0 or later. If immediate upgrade is not possible, disable automatic content decoding for responses from untrusted sources by setting decode_content=False or reject streamed responses using Deflate content encoding. Applications disabling automatic decoding must handle compressed responses safely at another layer.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
BREW-pdfly-CVE-2026-97688
Osv Schema Version
1.7.3
Ecosystems
["Homebrew"]
Cvss Version
4.0

Threat ID: 6ac1396aa43b0b3b89d5fbd3

Added to database: 10/03/2026, 17:20:42 UTC

Last enriched: 10/03/2026, 17:33:26 UTC

Last updated: 10/04/2026, 02:46:08 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses