This CVE has been withdrawn by MITRE
MITRE marked CVE-2026-9375 as REJECTED on . There is no longer a valid blast radius to assess. Any historical package or vendor data shown below is preserved for audit reference only.
Reason given by MITRE
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-9375 Blast Radius
✕ WITHDRAWN — HISTORICAL DATAurllib3 version 2.6.3 is vulnerable to a decompression bomb bypass in its streaming API (`preload_content=False`) when using Brotli support. The issue…