Pdfly: urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory (CVE-2026-97689)
urllib3 versions prior to 2.8.0 have a vulnerability in their streaming API when handling chunked-transfer-encoded HTTP responses. The issue arises because the chunk-size field can be excessively large without newlines, causing unbounded memory buffering. This affects the read_chunked() and stream() methods, potentially leading to high memory consumption when processing maliciously crafted HTTP responses. The vulnerability is fixed in urllib3 2.8.0 by rejecting chunk-size fields larger than 65536 bytes.
AI Analysis
Technical Summary
The urllib3 library's streaming API reads chunked-transfer-encoded HTTP responses by buffering the chunk-size field until a newline or EOF is encountered. A malicious HTTP server can exploit this by sending a very long chunk-size field without newlines, causing urllib3 to buffer an unbounded amount of data in memory. This vulnerability affects urllib3 versions before 2.8.0, specifically impacting the read_chunked() and stream() methods. The fix implemented in version 2.8.0 rejects chunk-size fields larger than 65536 bytes, preventing excessive memory allocation. The issue does not affect the chunk data itself, only the chunk-size field parsing.
Potential Impact
Applications and libraries using urllib3 versions earlier than 2.8.0 that stream chunked HTTP responses from untrusted sources may experience excessive memory usage due to unbounded buffering of the chunk-size field. This can lead to denial of service by resource exhaustion. Non-malicious servers are not impacted. The vulnerability also affects the requests library streaming API, which relies on urllib3.
Mitigation Recommendations
Upgrade to urllib3 version 2.8.0 or later, where chunk-size fields larger than 65536 bytes are rejected to prevent unbounded memory buffering. If immediate upgrade is not possible, avoid using the streaming API methods read_chunked() and stream() on untrusted sources and instead read the entire response at once using the read() method.
Pdfly: urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory (CVE-2026-97689)
Description
urllib3 versions prior to 2.8.0 have a vulnerability in their streaming API when handling chunked-transfer-encoded HTTP responses. The issue arises because the chunk-size field can be excessively large without newlines, causing unbounded memory buffering. This affects the read_chunked() and stream() methods, potentially leading to high memory consumption when processing maliciously crafted HTTP responses. The vulnerability is fixed in urllib3 2.8.0 by rejecting chunk-size fields larger than 65536 bytes.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The urllib3 library's streaming API reads chunked-transfer-encoded HTTP responses by buffering the chunk-size field until a newline or EOF is encountered. A malicious HTTP server can exploit this by sending a very long chunk-size field without newlines, causing urllib3 to buffer an unbounded amount of data in memory. This vulnerability affects urllib3 versions before 2.8.0, specifically impacting the read_chunked() and stream() methods. The fix implemented in version 2.8.0 rejects chunk-size fields larger than 65536 bytes, preventing excessive memory allocation. The issue does not affect the chunk data itself, only the chunk-size field parsing.
Potential Impact
Applications and libraries using urllib3 versions earlier than 2.8.0 that stream chunked HTTP responses from untrusted sources may experience excessive memory usage due to unbounded buffering of the chunk-size field. This can lead to denial of service by resource exhaustion. Non-malicious servers are not impacted. The vulnerability also affects the requests library streaming API, which relies on urllib3.
Mitigation Recommendations
Upgrade to urllib3 version 2.8.0 or later, where chunk-size fields larger than 65536 bytes are rejected to prevent unbounded memory buffering. If immediate upgrade is not possible, avoid using the streaming API methods read_chunked() and stream() on untrusted sources and instead read the entire response at once using the read() method.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-pdfly-CVE-2026-97689
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 4.0
Threat ID: 6ac1396aa43b0b3b89d5fbd2
Added to database: 10/03/2026, 17:20:42 UTC
Last enriched: 10/03/2026, 17:33:17 UTC
Last updated: 10/04/2026, 02:46:08 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.