CVE-2026-97689 | urllib3 up to 2.7.x streaming chunk parser HTTPResponse.read_chunked/HTTPResponse.stream chunk-size allocation of resources
A vulnerability was found in urllib3 up to 2.7.x. It has been rated as problematic. The affected element is the function HTTPResponse.read_chunked/HTTPResponse.stream of the component streaming chunk parser. This manipulation of the argument chunk-size causes allocation of resources.
The identification of this vulnerability is CVE-2026-97689. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More