CVE-2026-97688 | urllib3 up to 2.7.x Deflate decoder HTTPResponse.stream/HTTPResponse.read_chunked infinite loop

SecurityVulns

A vulnerability was found in urllib3 up to 2.7.x. It has been declared as problematic. Impacted is the function HTTPResponse.stream/HTTPResponse.read_chunked of the component Deflate decoder. The manipulation results in infinite loop.

This vulnerability was named CVE-2026-97688. The attack may be performed from remote. There is no available exploit.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More