Skip to main content

Loop with Unreachable Exit Condition ('Infinite Loop') in urllib3

CVE-2026-97688

  • urllib3
Severity Medium
Score 6.9/10

Summary

urllib3 is an HTTP client library for Python. In versions 2.6.2 prior to 2.8.0, `HTTPResponse.stream` and `HTTPResponse.read_chunked` can enter an infinite loop because the Deflate decoder retains trailing bytes as unconsumed input after reaching end-of-stream and repeatedly decodes them without progress. The issue occurs when an untrusted server sends a chunked Deflate response whose decoded body exceeds a positive finite chunk size and whose encoded body has trailing bytes, specifically a response with `Transfer-Encoding: chunked` and `Content-Encoding: deflate`, content decoding enabled, and the positive finite amt=N streaming chunk size. The attack mechanism is that a malicious server returns a compressed chunked response with trailing bytes after the Deflate stream. The impact is excessive CPU usage and a request that does not complete, and network read timeouts do not interrupt the loop because no further socket read occurs. This issue is fixed in version 2.8.0.

  • LOW
  • NETWORK
  • NONE
  • NONE

CWE-835 - Loop with Unreachable Exit Condition

Loops with multiple exits and flags detract from the quality of an application. They tend to make control structures difficult to understand, and introduce the risk of non-termination and other structural problems. The vulnerability “loop with unreachable exit condition” enables attackers to exploit this flaw, leading to denial of service.

Advisory Timeline

  • Published