{"id":"CVE-2025-66418","aliases":["GHSA-gm62-xv2j-4w53","PYSEC-2026-1998"],"url":"https://o3.security/vulnerability/CVE-2025-66418","summary":"urllib3 allows an unbounded number of links in the decompression chain","details":"urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.","published":"2025-12-05T16:02:15.271Z","modified":"2026-08-08T03:48:05.796238561Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"urllib3","fixedVersion":"2.6.0"}],"fix":{"url":"https://github.com/urllib3/urllib3/commit/24d7b67eac89f94e11003424bcf0d8f7b72222a8","label":"urllib3/urllib3@24d7b67"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66418.json"},{"type":"ADVISORY","url":"https://github.com/urllib3/urllib3/security/advisories/GHSA-gm62-xv2j-4w53"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66418"},{"type":"FIX","url":"https://github.com/urllib3/urllib3/commit/24d7b67eac89f94e11003424bcf0d8f7b72222a8"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:48:05.796238561Z"}}