天下漏洞,尽知其名
MEDIUM

CVE-2026-97688 urllib3 拒绝服务漏洞

影响恶意服务器可致客户端 CPU 耗尽且请求无法完成

MEDIUM
暂无 CVSS 评分
AI 研判

urllib3 是 Python 的 HTTP 客户端库。在 2.6.2 至 2.8.0 之前的版本中,HTTPResponse.stream 和 HTTPResponse.read_chunked 在处理带尾随字节的 Deflate 分块响应时可能陷入无限循环。该问题已在 2.8.0 版本修复。

影响范围

urllib3

urllib3 2.6.2 起至 2.8.0 之前的版本受影响,2.8.0 已修复。

漏洞详情

当服务器返回 Transfer-Encoding: chunked 且 Content-Encoding: deflate 的响应、启用内容解码并使用正有限值 amt=N 的分块流式读取时,Deflate 解码器在到达流末尾后仍保留尾随字节作为未消费输入,反复解码却无进展,从而形成无限循环。由于循环中不再进行 socket 读取,网络读超时也无法中断。

利用条件与风险

利用前提是客户端连接不可信服务器并以上述方式流式读取响应,攻击者可借此造成客户端 CPU 资源耗尽和请求挂起,属于拒绝服务风险。

修复建议

升级到 urllib3 2.8.0 或更高版本;临时缓解可避免对不可信来源使用分块 Deflate 流式解码,或对响应大小与解码进度设置外部限制。

原始情报

urllib3 is an HTTP client library for Python. From 2.6.2 until 2.8.0, HTTPResponse.stream and HTTPResponse.read_chunked can enter an infinite loop because the Deflate decoder retains trailing bytes as unconsumed input after reaching end-of-stream and repeatedly decodes them without progress. The issue occurs when an untrusted server sends a chunked Deflate response whose decoded body exceeds a positive finite chunk size and whose encoded body has trailing bytes, specifically a response with Transfer-Encoding: chunked and Content-Encoding: deflate, content decoding enabled, and the positive finite amt=N streaming chunk size. The attack mechanism is that a malicious server returns a compressed chunked response with trailing bytes after the Deflate stream. The impact is excessive CPU usage and a request that does not complete, and network read timeouts do not interrupt the loop because no further socket read occurs. This issue is fixed in version 2.8.0.