urllib3, Infinite Loop (Denial of Service), CVE-2026-97688 (Medium) -DC-Sep2026-2673

Listen to this Post

urllib3 is a widely used HTTP client library for Python that provides efficient handling of large HTTP responses through its streaming API. The streaming API reads response content in chunks rather than loading the entire body into memory at once, which is essential for applications processing large data streams from remote servers. urllib3 can automatically decompress response bodies based on the HTTP Content-Encoding header. When a compressed, chunked response is received, urllib3 first consumes data already buffered by the decoder before reading the next HTTP chunk from the network. This design allows for memory-efficient processing of compressed data arriving in a streaming fashion.
However, urllib3 versions from 2.6.2 through 2.7.0 could enter an infinite loop when processing a chunked response that contained bytes after the end of the Deflate stream. The vulnerability manifests when a malicious or misbehaving server sends a response with Transfer-Encoding: chunked and Content-Encoding: deflate. If the decompressed body exceeds the requested streaming chunk size, Python’s zlib implementation could retain the trailing bytes as unconsumed input after reaching the end of the compressed stream. The Deflate decoder in urllib3 would then repeatedly attempt to decode those same trailing bytes without making any forward progress or reading additional data from the network.
The core issue lies in the interaction between urllib3’s chunked reading logic and Python’s zlib module. When the decoder reaches the end of the Deflate stream, any remaining bytes in the input buffer are technically invalid or extraneous. A correctly implemented decoder should recognize that the stream has ended and stop processing, potentially discarding the trailing bytes or raising an error. Instead, the affected urllib3 versions would retain those bytes as unconsumed input and repeatedly feed them back into the zlib decompressor. Since zlib cannot produce any further decoded output from these trailing bytes, the decoder reports that no progress was made, yet urllib3’s loop continues to call the decoder again with the same input, creating a tight infinite loop.
This behavior has severe consequences for client applications. The infinite loop consumes CPU cycles continuously without ever completing the request. Because the loop does not require any further socket operations—the data is already in memory—network read timeouts do not trigger and cannot interrupt the loop. An attacker controlling a malicious server can exploit this by sending a specially crafted response to any application using the vulnerable urllib3 version, causing excessive CPU usage and preventing the affected request from completing. In high-throughput environments, this can lead to denial of service conditions, thread exhaustion, and connection pool depletion.
The vulnerability is classified under CWE-835: Loop with Unreachable Exit Condition (‘Infinite Loop’), which describes loops that consume excessive resources without making progress toward termination. This flaw aligns with ATT&CK technique T1496, Resource Hijacking, specifically sub-technique T1496.002 for denial of service through resource exhaustion. The issue was fixed in urllib3 2.8.0, where the Deflate decoder was modified to stop accepting input after reaching the end of the compressed stream and to no longer report trailing bytes as data that can produce more decoded output.

DailyCVE Form:

Platform: urllib3
Version: 2.6.2–2.7.0
Vulnerability : CVE-2026-97688
Severity: Medium
date: 2026-09-29

Prediction: Patch expected 2026-09-15

What Undercode Say: Analytics

Bash command to check installed urllib3 version:

python -c "import urllib3; print(urllib3.<strong>version</strong>)"

Command to test the vulnerable endpoint with curl:

curl -v --http1.1 -H "Accept-Encoding: deflate" http://malicious-server.example.com/stream

Python code snippet to reproduce the infinite loop condition:

import urllib3
http = urllib3.PoolManager()
response = http.request(
"GET",
"http://malicious-server.example.com/stream",
preload_content=False,
decode_content=True,
headers={"Accept-Encoding": "deflate"}
)
for chunk in response.stream(amt=1024):
print(len(chunk))

How Exploit: (Educational Purposes!)

A malicious server can trigger the vulnerability by sending a chunked HTTP response with the following characteristics: the response uses Transfer-Encoding: chunked and Content-Encoding: deflate, the decoded body exceeds the requested streaming chunk size, and the encoded body contains trailing bytes after the end of the Deflate stream. The server first sends a valid Deflate-compressed payload that decompresses to a size larger than the client’s chunk size. After the Deflate stream ends, the server appends additional bytes within the chunked transfer encoding. When the client’s urllib3 library processes this response using HTTPResponse.stream() or HTTPResponse.read_chunked(), the decoder retains the trailing bytes as unconsumed input and enters an infinite loop attempting to decode them. The client application becomes stuck consuming CPU resources indefinitely.

Protection: from this CVE

Upgrade to urllib3 version 2.8.0 or later, which contains the fix that stops the Deflate decoder from accepting input after the end of the compressed stream. If upgrading is not immediately possible, disable automatic content decoding for responses from untrusted sources by setting decode_content=False when making requests. Alternatively, reject streamed responses that use the Deflate content encoding entirely. Applications that disable automatic decoding must handle the compressed response safely at another layer, ensuring that no untrusted Deflate-encoded data is processed without proper safeguards.

Impact:

A malicious server can cause excessive CPU usage on the client by preventing the affected request from completing. Network read timeouts do not interrupt the infinite loop because no further socket operation is required. The vulnerability leads to denial of service conditions, potentially exhausting connection pools or thread resources in high-throughput environments. The affected request never completes, causing application-level timeouts rather than network-level interruptions.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top