PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-44432 urllib3 CVE debrief

CVE-2026-44432 is a vulnerability in the urllib3 library for Python, which could lead to excessive resource consumption due to improper decompression of HTTP responses. The vulnerability affects versions from 2.6.0 to before 2.7.0. An attacker could exploit this vulnerability by sending a highly compressed response, causing the client to consume high CPU and allocate a large amount of memory. The issue is fixed in version 2.7.0.

Vendor
urllib3
Product
Unknown
CVSS
HIGH 8.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-13
Original CVE updated
2026-09-10
Advisory published
2026-05-13
Advisory updated
2026-09-10

Who should care

Users of the urllib3 library in Python, particularly those using versions between 2.6.0 and 2.7.0, should be aware of this vulnerability and take steps to mitigate it. This includes updating to version 2.7.0 or applying patches provided by the vendor. Organizations using affected versions should prioritize patching to prevent potential resource exhaustion attacks.

Technical summary

The urllib3 library for Python, versions from 2.6.0 to before 2.7.0, has a vulnerability that allows for improper decompression of HTTP responses. This can occur during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially. The vulnerability can lead to excessive resource consumption, including high CPU usage and massive memory allocation for the decompressed data, on the client side. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 8.9, indicating a high severity.

Defensive priority

High priority should be given to patching or mitigating this vulnerability, as it can lead to resource exhaustion attacks. Updating to version 2.7.0 of the urllib3 library is recommended.

Recommended defensive actions

  • Update to urllib3 version 2.7.0 or later
  • Apply patches provided by the vendor
  • Monitor for and limit highly compressed responses
  • Implement resource limits for HTTP responses
  • Regularly review and update dependencies

Evidence notes

The CVE record and NVD detail provide information on the vulnerability, its impact, and the affected versions. The vendor advisory on GitHub and Red Hat errata provide mitigation and patch information.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-44432 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-44432

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-44432 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-44432

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j

    [email protected] - Mitigation, Vendor Advisory

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:15862

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:20338

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:22934

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:24000

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:24009

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:24014

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.