Two critical vulnerabilities have been identified in the Python HTTP client library urllib3, affecting versions from 1.0 up to but not including 2.6.0. The first vulnerability (CVE-2025-66471) involves the Streaming API's improper handling of highly compressed data, which can result in excessive resource consumption such as high CPU usage and massive memory allocation. This flaw allows a remote attacker to exploit the decompression logic, potentially leading to denial-of-service (DoS) conditions on affected systems.
The second vulnerability (CVE-2025-66418) allows a malicious server to insert an unbounded number of links in the decompression chain, again resulting in high CPU usage and memory exhaustion. Both vulnerabilities are remotely exploitable and have been addressed in urllib3 version 2.6.0. Organizations using affected versions should update immediately to mitigate the risk of DoS attacks stemming from these decompression and streaming flaws.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
A follow-up security report summarized the two urllib3 flaws as client denial-of-service risks stemming from unbounded decompression and streaming resource exhaustion, reinforcing the recommendation to upgrade to version 2.6.0 or later. This was reporting on the already disclosed vulnerabilities rather than a new incident.
A second high-severity urllib3 vulnerability affecting versions 1.0 through before 2.6.0 was disclosed, showing that the Streaming API could fully decode highly compressed responses in one operation while satisfying chunk requests. This could let a malicious server cause excessive CPU and memory consumption through decompressed data amplification.
A high-severity vulnerability affecting urllib3 versions 1.24 through before 2.6.0 was disclosed, describing how a malicious server could trigger virtually unlimited decompression steps, causing high CPU use and massive memory allocation. The issue was categorized as remotely exploitable denial of service under CWE-770.
The Python HTTP client library urllib3 released version 2.6.0 to fix two denial-of-service issues: an unbounded decompression-chain flaw (CVE-2025-66418) and a Streaming API resource-exhaustion flaw involving highly compressed responses (CVE-2025-66471). The fixes are referenced by upstream commits and GitHub Security Advisories.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.