| Release Date: | 2025-12-05 | |
| Impact: | Important | What is this? |
urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.
See more information about CVE-2025-66418 from MITRE CVE dictionary and NIST NVD
NOTE: The following CVSS metrics and score provided are preliminary and subject to review.
| Base Score: | 7.5 |
| Vector String: | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| Version: | 3.1 |
| Attack Vector: | Network |
| Attack Complexity: | Low |
| Privileges Required: | None |
| User Interaction: | None |
| Scope: | Unchanged |
| Confidentiality Impact: | None |
| Integrity Impact: | None |
| Availability Impact: | High |
| Platform | Errata | Release Date |
| Oracle Linux version 10 (python-urllib3) | ELSA-2026-1086 | 2026-01-26 |
| Oracle Linux version 8 (fence-agents) | ELSA-2026-1240 | 2026-01-27 |
| Oracle Linux version 8 (python-urllib3) | ELSA-2026-1254 | 2026-01-26 |
| Oracle Linux version 8 (python3.11-urllib3) | ELSA-2026-1224 | 2026-01-26 |
| Oracle Linux version 8 (python3.12-urllib3) | ELSA-2026-1226 | 2026-01-26 |
| Oracle Linux version 8 (resource-agents) | ELSA-2026-1241 | 2026-01-26 |
| Oracle Linux version 9 (fence-agents) | ELSA-2026-1239 | 2026-01-27 |
| Oracle Linux version 9 (python-urllib3) | ELSA-2026-1087 | 2026-01-26 |
| Oracle Linux version 9 (python3.11-urllib3) | ELSA-2026-1089 | 2026-01-26 |
| Oracle Linux version 9 (python3.12-urllib3) | ELSA-2026-1088 | 2026-01-26 |
This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections: