CVE-2026-97689 urllib3 内存耗尽漏洞
影响恶意服务器可耗尽客户端进程内存,导致拒绝服务
urllib3 是 Python 的 HTTP 客户端库。在 1.10.3 至 2.8.0 之前的版本中,HTTPResponse.read_chunked 和 HTTPResponse.stream 方法在解析分块传输编码时,会无长度限制地缓冲 chunk-size 字段直到遇到换行或 EOF。恶意服务器返回 Transfer-Encoding: chunked 并发送超长且无换行的字节序列,即可触发无界内存分配。
影响范围
urllib3 1.10.3 至 2.8.0 之前的版本;2.8.0 已修复。
漏洞详情
漏洞类型为无界资源分配(内存耗尽)。成因是分块传输编码解析器在读取 chunk-size 行时未设置长度上限,会持续缓冲数据直到换行符或连接结束。攻击者只需控制或劫持 HTTP 服务端,返回 chunked 编码并发送一条超长且不含换行的 chunk-size 行,客户端便会不断分配内存直至进程崩溃或被系统杀死。
利用条件与风险
利用前提是客户端连接恶意或被劫持的 HTTP 服务器并读取分块响应。实战中可造成客户端进程内存耗尽、服务不可用,属于拒绝服务风险。
修复建议
升级 urllib3 至 2.8.0 或更高版本。临时缓解措施包括限制单次响应读取大小、设置超时,或避免连接不可信服务器,暂无其他公开缓解方案。
urllib3 is an HTTP client library for Python. From 1.10.3 until 2.8.0, the HTTPResponse.read_chunked and HTTPResponse.stream methods can allocate unbounded memory because the streaming chunk parser buffers the chunk-size field until newline or EOF without a length bound. The trigger is that a malicious server returns Transfer-Encoding: chunked followed by a very long run of bytes without a newline. The attack mechanism is that a malicious HTTP server sends a very long unterminated chunk-size line. The impact is that unbounded memory allocation can exhaust the client process. This issue is fixed in version 2.8.0.