urllib3 version 2.6.3 is vulnerable to a decompression bomb bypass in its streaming API (preload_content=False) when using Brotli support. The issue arises due to three independent code paths in response.py that bypass the max_length protection introduced in version 2.6.0 to mitigate CVE-2025-66471. Specifically, negative max_length values can be produced due to buffer arithmetic in read(), flush_decoder unconditionally overrides max_length to -1, and _flush_decoder() passes no limit at all, defaulting to unlimited decompression. This allows a malicious HTTP server to trigger an out-of-memory (OOM) condition by decompressing large payloads into memory, leading to a denial of service (DoS). The vulnerability affects urllib3 2.6.3 and Brotli 1.2.0 and impacts applications and libraries using requests or urllib3 to stream content from untrusted sources.
This CVE has been withdrawn by MITRE
MITRE marked CVE-2026-9375 as REJECTED on . It is no longer considered a valid vulnerability record. The original content below is preserved for historical reference only.
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-9375
- High severity, but no confirmed exploitation yet
A fix is available — apply it.
- CVSS v3
- 7.5
- EchelonGraph score
- Not yet assessedThis CVE record was withdrawn by its numbering authority, so there is no vulnerability to rate.
- EG Score
- —
- EG Risk
- —
- EPSS PROB
- 0.3%
- EPSS %ILE
- 22nd
- KEV
- Not listed
Published
June 19, 2026
Last Modified
June 22, 2026
Advisory Details (2)
Auto-updated Jun 22, 2026huntr - The world's first bug bounty platform for AI/ML
https://huntr.com/bounties/ddd09eb9-b87d-4a43-84df-48837b1bbc23commit 2bdcc44d1e16 (urllib3/urllib3)
Patch available: urllib3/urllib3 2.7.0 (contains commit 2bdcc44d1e16)
https://github.com/urllib3/urllib3/commit/2bdcc44d1e163fb5cc48a8662425e35e15adfe6aVendor Advisories for CVE-2026-9375(3)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
- RHSA-2026:69289Red Hat Product SecurityHigh
Red Hat Security Advisory: A Subscription Management tool for finding and reporting Red Hat product usage
- RHSA-2026:53459Red Hat Product SecurityHigh
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
- GHSA-mwq6-fg78-p6cqGitHub Security AdvisoriesHigh
urllib3 version 2.6.3 is vulnerable to a decompression bomb bypass in its streaming API (...
Affected Packages
(4 across 4 ecosystems)
Debian:11(1)
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| python-urllib3 | 1.26.12-1 ... 2.7.0-3 (29 versions) |
| — |
Debian:12(1)
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| python-urllib3 | 1.26.12-1 ... 2.7.0-3 (26 versions) |
| — |
Debian:13(1)
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| python-urllib3 | 2.3.0-3 ... 2.7.0-3 (11 versions) |
| — |
Debian:14(1)
| Package | Vulnerable range | Fix by version range | Dependents |
|---|---|---|---|
| python-urllib3 | 2.3.0-3 ... 2.6.3-2 (6 versions) |
| — |
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 1× in last 7d / 2× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 168 total refreshes for this CVE.
- 2026-10-02 15:10 UTCOSV refresh
- 2026-09-13 13:00 UTCGHSA enrichment
- 2026-08-30 20:45 UTCGHSA enrichment
- 2026-08-23 11:07 UTCGHSA enrichment
- 2026-08-20 07:59 UTCGHSA enrichment
- 2026-08-17 04:18 UTCGHSA enrichment
- 2026-08-14 01:09 UTCEG score recompute▼ 7.50
- 2026-08-14 01:09 UTCGHSA enrichment
- 2026-08-13 22:00 UTCEPSS rescore
- 2026-08-13 12:42 UTCGHSA enrichment
- 2026-08-13 00:02 UTCEG score recompute
- 2026-08-13 00:02 UTCGHSA enrichment
- 2026-08-12 13:51 UTCEPSS rescore
- 2026-08-12 11:36 UTCGHSA enrichment
- 2026-08-11 23:09 UTCEG score recompute
- 2026-08-11 23:09 UTCGHSA enrichment
- 2026-08-11 13:43 UTCEPSS rescore
- 2026-08-11 10:42 UTCEG score recompute
- 2026-08-11 10:42 UTCGHSA enrichment
- 2026-08-11 00:00 UTCEPSS rescore
- 2026-08-10 22:15 UTCGHSA enrichment
- 2026-08-10 09:47 UTCGHSA enrichment
- 2026-08-09 21:21 UTCEG score recompute
- 2026-08-09 21:21 UTCGHSA enrichment
- 2026-08-09 13:47 UTCEPSS rescore
Show 75 moreShow fewer
- 2026-08-09 08:54 UTCGHSA enrichment
- 2026-08-08 20:27 UTCEG score recompute
- 2026-08-08 20:27 UTCGHSA enrichment
- 2026-08-08 16:37 UTCEPSS rescore
- 2026-08-08 07:59 UTCGHSA enrichment
- 2026-08-07 19:32 UTCEG score recompute
- 2026-08-07 19:32 UTCGHSA enrichment
- 2026-08-07 16:30 UTCEPSS rescore
- 2026-08-07 07:05 UTCGHSA enrichment
- 2026-08-06 18:38 UTCEG score recompute
- 2026-08-06 18:38 UTCGHSA enrichment
- 2026-08-06 13:47 UTCEPSS rescore
- 2026-08-06 06:11 UTCEG score recompute
- 2026-08-06 06:11 UTCGHSA enrichment
- 2026-08-05 19:17 UTCEPSS rescore
- 2026-08-05 19:17 UTCEPSS rescore
- 2026-08-05 17:45 UTCGHSA enrichment
- 2026-08-05 03:59 UTCGHSA enrichment
- 2026-08-04 15:33 UTCEG score recompute
- 2026-08-04 15:32 UTCGHSA enrichment
- 2026-08-04 15:10 UTCEPSS rescore
- 2026-08-04 10:39 UTCEPSS rescore
- 2026-08-04 03:06 UTCGHSA enrichment
- 2026-08-03 14:38 UTCEG score recompute
- 2026-08-03 14:38 UTCGHSA enrichment
- 2026-08-03 10:36 UTCEPSS rescore
- 2026-08-03 02:11 UTCGHSA enrichment
- 2026-08-02 13:44 UTCEG score recompute
- 2026-08-02 13:44 UTCGHSA enrichment
- 2026-08-02 02:27 UTCEPSS rescore
- 2026-08-02 01:16 UTCGHSA enrichment
- 2026-08-01 12:49 UTCEG score recompute
- 2026-08-01 12:49 UTCGHSA enrichment
- 2026-08-01 04:16 UTCEPSS rescore
- 2026-08-01 00:21 UTCGHSA enrichment
- 2026-07-31 11:51 UTCGHSA enrichment
- 2026-07-30 22:17 UTCEG score recompute
- 2026-07-30 22:16 UTCGHSA enrichment
- 2026-07-30 16:28 UTCEPSS rescore
- 2026-07-30 02:53 UTCEG score recompute
- 2026-07-30 02:53 UTCGHSA enrichment
- 2026-07-30 01:30 UTCEPSS rescore
- 2026-07-29 14:00 UTCGHSA enrichment
- 2026-07-29 01:33 UTCEG score recompute
- 2026-07-29 01:33 UTCGHSA enrichment
- 2026-07-28 15:37 UTCEPSS rescore
- 2026-07-28 09:49 UTCGHSA enrichment
- 2026-07-27 21:17 UTCEG score recompute
- 2026-07-27 21:17 UTCGHSA enrichment
- 2026-07-27 14:14 UTCEPSS rescore
- 2026-07-27 06:40 UTCGHSA enrichment
- 2026-07-26 16:47 UTCEG score recompute
- 2026-07-26 16:47 UTCGHSA enrichment
- 2026-07-26 14:54 UTCEPSS rescore
- 2026-07-25 14:18 UTCEPSS rescore
- 2026-07-24 14:18 UTCEPSS rescore
- 2026-07-23 14:18 UTCEPSS rescore
- 2026-07-23 03:23 UTCEG score recompute
- 2026-07-22 14:08 UTCEPSS rescore
- 2026-07-21 15:25 UTCEPSS rescore
- 2026-07-21 15:25 UTCEPSS rescore
- 2026-07-20 17:08 UTCEPSS rescore
- 2026-07-19 14:31 UTCEPSS rescore
- 2026-07-19 02:29 UTCEPSS rescore
- 2026-07-18 10:04 UTCEPSS rescore
- 2026-07-16 23:48 UTCGHSA enrichment
- 2026-07-16 17:03 UTCEPSS rescore
- 2026-07-16 11:21 UTCGHSA enrichment
- 2026-07-15 22:16 UTCGHSA enrichment
- 2026-07-15 16:57 UTCEPSS rescore
- 2026-07-15 09:48 UTCGHSA enrichment
- 2026-07-15 02:00 UTCEPSS rescore
- 2026-07-14 21:21 UTCGHSA enrichment
- 2026-07-14 08:54 UTCGHSA enrichment
- 2026-07-13 22:31 UTCEPSS rescore
Related CVEs(same product + same CWE)
Same product
10 shownDebian:11:python-urllib3
Frequently asked(5)
What is CVE-2026-9375?
When was CVE-2026-9375 disclosed?
Is CVE-2026-9375 actively exploited?
What is the CVSS score of CVE-2026-9375?
How do I remediate CVE-2026-9375?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-9375
Is Your Infrastructure Affected by CVE-2026-9375?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.