cbcvebase.
CVE-2025-66418
published 2025-12-05

CVE-2025-66418: urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was…

PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.63%
46.3th percentile
urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianpython-urllib3< python-urllib3 1.26.12-1+deb12u2 (bookworm)python-urllib3 1.26.12-1+deb12u2 (bookworm)
msrcazl3_python-urllib3_2.0.7-2_on_azure_linux_3.0
msrcazl3_tensorflow_2.16.1-9_on_azure_linux_3.0
msrccbl2_python-urllib3_1.26.19-2_on_cbl_mariner_2.0
msrccbl2_python-urllib3_1.26.19-3_on_cbl_mariner_2.0
msrccbl2_python-virtualenv_20.26.6-2_on_cbl_mariner_2.0
pythonurllib3>= 1.24 < 2.6.02.6.0
ubuntupython-pip
urllib3urllib3
urllib3urllib3>= 1.24 < 2.6.02.6.0

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.08.9HIGHCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv8.9HIGH
vendor_debian8.9HIGH
vendor_msrc8.9HIGH
vendor_redhat8.9HIGH
vendor_oracle7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.