PatchSiren cyber security CVE debrief
CVE-2026-44432 urllib3 CVE debrief
CVE-2026-44432 is a vulnerability in the urllib3 library for Python, which could lead to excessive resource consumption due to improper decompression of HTTP responses. The vulnerability affects versions from 2.6.0 to before 2.7.0. An attacker could exploit this vulnerability by sending a highly compressed response, causing the client to consume high CPU and allocate a large amount of memory. The issue is fixed in version 2.7.0.
- Vendor
- urllib3
- Product
- Unknown
- CVSS
- HIGH 8.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-13
- Original CVE updated
- 2026-09-10
- Advisory published
- 2026-05-13
- Advisory updated
- 2026-09-10
Who should care
Users of the urllib3 library in Python, particularly those using versions between 2.6.0 and 2.7.0, should be aware of this vulnerability and take steps to mitigate it. This includes updating to version 2.7.0 or applying patches provided by the vendor. Organizations using affected versions should prioritize patching to prevent potential resource exhaustion attacks.
Technical summary
The urllib3 library for Python, versions from 2.6.0 to before 2.7.0, has a vulnerability that allows for improper decompression of HTTP responses. This can occur during the second HTTPResponse.read(amt=N) call when the response was decompressed using the official Brotli library or when HTTPResponse.drain_conn() was called after the response had been read and decompressed partially. The vulnerability can lead to excessive resource consumption, including high CPU usage and massive memory allocation for the decompressed data, on the client side. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 8.9, indicating a high severity.
Defensive priority
High priority should be given to patching or mitigating this vulnerability, as it can lead to resource exhaustion attacks. Updating to version 2.7.0 of the urllib3 library is recommended.
Recommended defensive actions
- Update to urllib3 version 2.7.0 or later
- Apply patches provided by the vendor
- Monitor for and limit highly compressed responses
- Implement resource limits for HTTP responses
- Regularly review and update dependencies
Evidence notes
The CVE record and NVD detail provide information on the vulnerability, its impact, and the affected versions. The vendor advisory on GitHub and Red Hat errata provide mitigation and patch information.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-44432 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-44432
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-44432 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-44432
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j
[email protected] - Mitigation, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:15862
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:20338
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:22934
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:24000
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:24009
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:24014
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.