GHSA-hmv2-79q8-fv6g is a high-severity (CVSS 7.5) Uncontrolled Resource Consumption vulnerability in urllib3. A fix is available for urllib3 — see the affected versions and patch details below.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
GHSA-hmv2-79q8-fv6g by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.
Where this sits among everything scored
Of 385,386 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.
Real-World Exposure
urllib3Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects PyPI packages — download data is not available via public APIs for these ecosystems.
Description
The _encode_invalid_chars function in util/url.py in the urllib3 library 1.25.2 through 1.25.7 for Python allows a denial of service (CPU consumption) because of an inefficient algorithm. The percent_encodings array contains all matches of percent encodings. It is not deduplicated. For a URL of length N, the size of percent_encodings may be up to O(N). The next step (normalize existing percent-encoded bytes) also takes up to O(N) for each step, so the total time is O(N^2). If percent_encodings were deduplicated, the time to compute _encode_invalid_chars would be O(kN), where k is at most 484 ((10+6*2)^2).
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🐍PyPI | urllib3 | ≥ 1.25.2&&< 1.25.8 | 1.25.8pip install --upgrade 'urllib3==1.25.8' |
Affected Products
urllib3pythonDetection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for urllib3, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update urllib3 to 1.25.8 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-hmv2-79q8-fv6g is resolved across your whole dependency graph.
Workarounds
Cap what an attacker can consume: apply request size, rate and timeout limits in front of the affected component, and run it with memory and CPU limits so exhaustion degrades one worker rather than the whole service.
Frequently Asked Questions
Is GHSA-hmv2-79q8-fv6g in your dependencies?
Find it across PyPI, including transitive dependencies.