天下漏洞,尽知其名
MEDIUM

CVE-2026-97689 urllib3 内存耗尽漏洞

影响恶意服务器可耗尽客户端进程内存,导致拒绝服务

MEDIUM
暂无 CVSS 评分
AI 研判

urllib3 是 Python 的 HTTP 客户端库。在 1.10.3 至 2.8.0 之前的版本中,HTTPResponse.read_chunked 和 HTTPResponse.stream 方法在解析分块传输编码时,会无长度限制地缓冲 chunk-size 字段直到遇到换行或 EOF。恶意服务器返回 Transfer-Encoding: chunked 并发送超长且无换行的字节序列,即可触发无界内存分配。

影响范围

urllib3

urllib3 1.10.3 至 2.8.0 之前的版本;2.8.0 已修复。

漏洞详情

漏洞类型为无界资源分配(内存耗尽)。成因是分块传输编码解析器在读取 chunk-size 行时未设置长度上限,会持续缓冲数据直到换行符或连接结束。攻击者只需控制或劫持 HTTP 服务端,返回 chunked 编码并发送一条超长且不含换行的 chunk-size 行,客户端便会不断分配内存直至进程崩溃或被系统杀死。

利用条件与风险

利用前提是客户端连接恶意或被劫持的 HTTP 服务器并读取分块响应。实战中可造成客户端进程内存耗尽、服务不可用,属于拒绝服务风险。

修复建议

升级 urllib3 至 2.8.0 或更高版本。临时缓解措施包括限制单次响应读取大小、设置超时,或避免连接不可信服务器,暂无其他公开缓解方案。

原始情报

urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk parser buffers the chunk-size field until newline or EOF without a length bound. The trigger is that a malicious server returns Transfer-Encoding: chunked followed by a very long run of bytes without a newline. The attack mechanism is that a malicious HTTP server sends a very long unterminated chunk-size line. The impact is that unbounded memory allocation can exhaust the client process. This issue is fixed in version 2.8.0.