CVE-2025-66418

Aliases:GHSA-gm62-xv2j-4w53PYSEC-2026-1998RHSA-2026:1329RHSA-2026:1330RHSA-2026:1331RHSA-2026:1332RHSA-2026:1336RHSA-2026:1337RHSA-2026:1338RHSA-2026:1339RHSA-2026:1340RHSA-2026:1701RHSA-2026:1702RHSA-2026:2279DEBIAN-CVE-2025-66418ALPINE-CVE-2025-66418CGA-2985-x9fq-mpvpCGA-2c98-m8qx-q62vCGA-2ff9-2934-gqc8CGA-2qhw-hw6w-2g5qCGA-2w6f-x3wh-hc9qCGA-2wg4-wq43-98hpCGA-2x99-34v2-5xw4CGA-2xfw-2cgh-7xwmCGA-32fq-9c22-44mjCGA-33xg-7mp7-pj64CGA-34wp-x5h3-x49qCGA-35mm-cvfw-xwgcCGA-3779-2p2h-qh56CGA-37hq-869r-pvx2CGA-3832-266h-4jgfCGA-3938-g24f-8h5rCGA-3cvc-v452-3c4pCGA-3fwx-2cxg-fm46CGA-3q67-3764-34gpCGA-44wc-p3fc-g66cCGA-479g-8h84-v5r5CGA-4c68-jcp6-jvm4CGA-4hj2-7hwv-3pjpCGA-4x9w-jwvq-mhrxCGA-54j2-8f9x-x4chCGA-55pv-xrpc-5ch8CGA-55vx-v6p5-2r95CGA-565v-679w-fx32CGA-568f-h889-r4wcCGA-56xw-g8mm-vqxcCGA-5gf4-j5rp-cqhwCGA-5h37-6xjv-hqv2CGA-5q6v-8c4p-ggcgCGA-5q77-mv3r-9mrwCGA-5qg6-24w4-66h9CGA-6q5g-rpj6-q588CGA-6r24-7wv5-w5x6CGA-6r7c-9v87-m87vCGA-6w29-77mf-wrxgCGA-73r6-f4x2-rj77CGA-76cx-8jxm-3pmjCGA-76jq-gg8h-67cmCGA-78gx-4pfp-vprcCGA-7c7g-v8c7-cp3hCGA-7ch7-vq85-wx6wCGA-7jhm-gcvr-9699CGA-7pp6-vxgf-996vCGA-8232-8863-qprxCGA-8262-fg5p-8958CGA-832w-9g5c-42x8CGA-8635-359h-27w7CGA-8639-7c3h-2hq6CGA-88r6-q244-g38jCGA-89cm-4pcg-6397CGA-8cjg-wvmf-92gqCGA-8m6v-m62j-gh37CGA-8pqv-hvgh-pv36CGA-8pvp-pcf2-g44cCGA-8q6r-mvqw-q3gfCGA-8r4f-f5w9-3vqgCGA-954p-f5q4-wgxxCGA-96f8-2w23-h2vqCGA-96xx-6p23-qmr8CGA-977h-3j66-82fcCGA-9789-22mq-8rw4CGA-98pv-4686-rp5hCGA-9cfm-xxxr-fg9qCGA-9g93-6rwm-hrq4CGA-9jh5-fx4m-qvxmCGA-9mp8-742g-xfp3CGA-9p8r-r9mh-6fj5CGA-c2mp-6mgj-gh6wCGA-c8g2-x92j-grpmCGA-c8h9-5476-mrp6CGA-c8rq-4hgg-7vj3CGA-ccvf-5c98-4h69CGA-cpwx-2m9v-36m5CGA-crvm-f52m-ch7hCGA-cv5c-gr9v-5cgpCGA-cwhg-997x-v4hrCGA-f9vm-whvp-q74gCGA-fcx2-rgff-6grwCGA-fm88-79r3-f23xCGA-fpr3-8j2r-g33qCGA-fvcp-24pr-59xfCGA-fvp9-qmq7-xxqrCGA-g2m2-hcch-x6gwCGA-g4v2-v856-89mwCGA-g7pg-wjwg-h3w7CGA-gc7f-p3qf-vqc5CGA-gvvj-562m-h8p7CGA-gxvf-x75r-q5chCGA-h3xq-69jg-vgqpCGA-h42g-7c82-4xc5CGA-h6x7-q684-v72gCGA-h9fw-vjc3-qxq6CGA-hcq9-55fm-9w39CGA-hggc-rxqg-ff9rCGA-hgqv-c34m-vv8cCGA-hvpj-7c2x-w9mhCGA-hw9p-4582-h5jwCGA-j6vx-9cp2-48pcCGA-j82w-7c8x-3gqvCGA-j96q-9qhp-pc6qCGA-jc5p-wgmv-4937CGA-jcjh-xff2-h5m8CGA-jf82-vq6j-f2xxCGA-jgmp-xgfw-p6vwCGA-jpc5-jjf9-r24vCGA-jqgc-8637-9q2mCGA-jvv9-pgvq-x545CGA-jwf2-ch87-34j6CGA-m47h-89cj-p82mCGA-m5c2-27hg-3mp7CGA-m7v7-frvf-r2xrCGA-mhrv-7vw9-x7h8CGA-mmj8-4c2q-ccvxCGA-mvgg-v8xf-25j9CGA-mxm5-7w9q-9wc9CGA-p272-xfr9-vx6rCGA-p7p9-xv7x-7xx2CGA-p9gv-jgvx-xg4gCGA-pcqc-5j8v-6xqqCGA-pg34-5qpq-7xfjCGA-pggm-4wjj-g2ccCGA-pp2h-7wcv-73x8CGA-pr6c-27pf-jv89CGA-prxp-gfjj-j45jCGA-pxvh-4r24-95fhCGA-25vm-c82g-22r3CGA-263g-9r6x-r9jrCGA-2phh-wc37-g3xgCGA-2w7v-c5h5-56vgCGA-34c8-83rq-pp64CGA-34hh-2pfr-qch2CGA-39vf-qv4x-94h9CGA-3xc4-59g8-g5xwCGA-4437-46qf-c98rCGA-4456-g355-mh5xCGA-4qmc-hr6p-9xvxCGA-4v4c-rhq7-9fv8CGA-4w5r-63p9-gfq7CGA-55r6-86xr-ffprCGA-56h5-ww9p-42m7CGA-58c3-3w23-qch2CGA-5c92-8w2h-638wCGA-5fhh-5cwp-cpw6CGA-5fjq-f39f-c666CGA-5g9x-r875-5cppCGA-5ggp-9rqj-2j9cCGA-5j6v-hgr4-rrhpCGA-5m4j-fcx2-mg7mCGA-5pcq-4m87-qg48CGA-5qrq-p896-c5v2CGA-5xxp-j2xv-58q6CGA-6839-2jfp-h98wCGA-68hw-h97f-hp35CGA-6qrw-6p25-x6m9CGA-6rj5-jq9f-45f9CGA-6wj4-7jm5-gfj7CGA-6wq4-xm38-c8mcCGA-725r-r4mm-4r23CGA-72gh-9pg6-48hjCGA-737p-5grh-55vwCGA-768w-9jfg-96gxCGA-76fw-cp3j-v7qwCGA-76rc-32hm-793jCGA-79h3-5cpp-q7xmCGA-79hx-fcp9-hr55CGA-7fx3-c6qc-73c2CGA-7g2w-5g23-75hcCGA-7h34-6jq5-w5vqCGA-7mj9-w448-fc5fCGA-7w5j-p4p8-xr6vCGA-7x22-wqfc-q4pvCGA-7xx4-wj87-3h8gCGA-82c8-g6f9-c2wmCGA-8395-78fx-9c26CGA-84mm-pm6c-7mwqCGA-87m6-jf67-h286CGA-897w-hjx6-8w9mCGA-89c6-mvmw-hw5fCGA-8hfg-p35q-2696CGA-8jrx-gwqf-cfphCGA-8p6p-fq8m-r86rCGA-8qfm-33qf-fxwrCGA-8vgr-g64r-jf67CGA-96hj-838j-mxpcCGA-9787-8q9g-3w9gCGA-97wg-j74m-5vqrCGA-9jc3-qch7-prmxCGA-9mr4-m545-mm66CGA-c26h-c7jg-hmcwCGA-c4jh-jcvg-p987CGA-c6mh-5xfq-h65gCGA-cgq9-6q3f-83qxCGA-chgj-g6xr-fm3hCGA-cmvr-hm7v-8j3qCGA-cphj-2p4v-pc4jCGA-cw67-9x29-759gCGA-f3r7-p22p-mx7mCGA-f4p9-qx84-3r28CGA-f5c5-cpwg-5gqfCGA-f723-jpwg-347wCGA-g58v-pf3m-g6cxCGA-g5m6-2qfm-x977CGA-g5wm-fpr7-j5xjCGA-g8q5-h83f-qfj2CGA-g9w9-j9jq-8m98CGA-gfmc-q54m-h8qgCGA-gj3r-57hj-6cvvCGA-gr2m-933j-3fgpCGA-h2rh-28fc-wcp2CGA-h3vm-hqq3-77c4CGA-h4g5-v76p-w635CGA-h6w5-3gj9-53v7CGA-h764-qjmx-h5gqCGA-h8vg-r8jc-p975CGA-h95q-fh9p-5w3jCGA-h9qm-98wv-p4vmCGA-hm95-85w6-2jg2CGA-hmv5-5372-r6m2CGA-hphg-q7vw-p786CGA-hv8f-958q-hfwfCGA-j2qc-mrcf-x6pxCGA-m354-h8p3-8294CGA-mc8f-6vcx-46m9CGA-mf96-mf4q-fq67CGA-mgf9-48w3-54x8CGA-mqvv-2xch-g8f3CGA-mr95-6cr4-mvv6CGA-mx88-pppw-wp93CGA-p3cc-2wx9-cjf8CGA-p5w6-83w8-m7x9CGA-p72p-x8fw-f6vxCGA-pfgh-7hpv-h4c5CGA-pm34-9ppj-4qjqCGA-pmxm-gr9m-r6fwCGA-pr53-vp4w-w3wfCGA-pvmr-6rgh-vv9jCGA-pw78-77x6-rmqhCGA-q27p-5mcm-5vgvCGA-q39q-974x-h6xxCGA-q3gg-wgx7-rhwcCGA-q3hj-vcph-gvx6CGA-q44v-wgcf-w696CGA-q466-fhcm-6gh8CGA-q63x-89q6-rc4pCGA-q6rg-r9j3-qh69CGA-q7hp-qhh3-g98cCGA-q9f6-wqxf-r9p6CGA-qc2m-f6jq-m666CGA-qc55-cp63-hhm3CGA-qj9c-xvph-rrwfCGA-qm38-m4hx-hpw6CGA-qqjc-3p57-whhmCGA-qw37-jwff-9gr3CGA-qw94-2prv-qpm5CGA-qwfh-m967-4563CGA-qxh6-v6ff-wp2rCGA-r43m-p532-5r7cCGA-r52c-v3qg-x7fcCGA-r83f-2xc5-69wcCGA-r83m-5696-fgh8CGA-r9m2-f538-3pqvCGA-rcq6-wp33-mpm7CGA-rcv8-6m38-9pq5CGA-rgww-3m3g-65f7CGA-rmm7-6x47-8x5jCGA-rpcx-5f2m-vxqqCGA-rr5h-fmrx-pch5CGA-rr72-xhj2-8m5wCGA-rrgr-7x48-pp9wCGA-rv35-9w8p-m7w6CGA-rv6q-3px8-cf48CGA-rxm3-x3qh-g8vhCGA-rxvp-2w47-93xrCGA-v4gv-p5xx-3r2qCGA-v577-mwvr-cqq3CGA-v86c-m99c-r9p9CGA-v8f6-mwmg-j2gxCGA-vh99-7p7w-96g6CGA-vj8m-3mh8-f2jxCGA-vpmr-c9h6-33xcCGA-vvfq-cwwr-wx9hCGA-w2xx-8982-2639CGA-w347-pr75-9qx4CGA-w38v-3rrj-fp72CGA-w8hg-rw2f-h79gCGA-w922-hmwm-rprmCGA-wcfj-9f4v-xvv6CGA-wf93-wf7g-j5q3CGA-wfm9-qvvr-cfg5CGA-wgf8-jjjf-84fgCGA-wj86-437j-x7f2CGA-wmj2-v768-f25cCGA-wp4x-8944-r265CGA-wpcr-rgjf-858wCGA-wr57-2qf8-gh5jCGA-wrw8-8jjq-pmhhCGA-ww49-5p6g-gh4qCGA-wx77-49xx-v6w5CGA-wx7f-vjc5-8q9cCGA-wxhj-crxp-v68vCGA-x3fh-3677-q3g8CGA-x5pq-ffvh-g8r5CGA-x6m6-pfx3-hvpgCGA-x75g-q5hf-ff9hCGA-x78j-xm2w-f673CGA-x9g9-8vw2-jffwCGA-xfwv-jj3r-m8mmCGA-xg44-23xf-q96gCGA-xgfh-hq4w-9vhpCGA-xm4j-x5cw-vqv6CGA-xmr5-9qx2-xrqfCGA-xp75-7jqv-j779CGA-xpq4-xw4h-qfjgCGA-xq3h-jww3-24pfCGA-xvgm-vjrh-32r3CGA-xwx6-w96r-87cwCGA-xxgf-h35v-v597CGA-6cm6-f95x-jv86
Analyzed
Published: 05 Dec 2025, 16:02
Last modified:05 Dec 2025, 18:15

Vulnerability Summary

Overall Risk (default)
medium
36/100
CVSS Score
8.9 HIGH
v4.0 (cve.org)
EPSS Score
0.68% LOW
1% probability +0.65%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

05 Dec 2025, 16:02
Published
Vulnerability first disclosed
05 Dec 2025, 18:15
Last Modified
Vulnerability information updated

Description

urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.

CVSS Metrics

  • v4.0HIGHScore: 8.9CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
  • v4.0HIGHScore: 8.9CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.68% Percentile: 51%

Techniques & Countermeasures

  • CWE-770Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Affected Systems

  • alpinepy3-urllib3

    < 2.6.3-r0

  • chainguardairflow-2

    < 2.11.0-r16

  • chainguardairflow-2-bitnami-compat

    < 2.11.0-r16

  • chainguardairflow-2-compat

    < 2.11.0-r16

  • chainguardairflow-2-iamguarded-compat

    < 2.11.0-r16

  • chainguardairflow-3

    < 3.1.4-r0

  • chainguardairflow-3-bitnami-compat

    < 3.1.4-r0

  • chainguardairflow-3-compat

    < 3.1.4-r0

  • chainguardairflow-3-iamguarded-compat

    < 3.1.4-r0

  • chainguardairflow-core-2

    < 2.11.0-r9

  • chainguardairflow-core-2-compat

    < 2.11.0-r9

  • chainguardairflow-core-2-oci-entrypoint

    < 2.11.0-r9

  • chainguardairflow-core-3

    < 3.1.3-r1

  • chainguardairflow-core-3-compat

    < 3.1.3-r1

  • chainguardairflow-core-3-oci-entrypoint

    < 3.1.3-r1

  • chainguardansible-operator

    < 1.42.2-r2 | < 1.42.0-r6

  • chainguardansible-operator-fips

    < 1.42.0-r1 | < 1.42.2-r2

  • chainguardapache-beam-python-3.11-sdk

    < 2.69.0-r2

  • chainguardauthentik

    < 2025.10.2-r3

  • chainguardauthentik-go-server

    < 2025.10.2-r3

  • chainguardawx

    < 24.6.1-r33 | < 24.6.1-r20

  • chainguardaz

    < 2.81.0-r1

  • chainguardazure-functions-host-python3.11-worker

    < 4.1048.200-r1

  • chainguardazure-functions-host-python3.12-worker

    < 4.1048.200-r1

  • chainguardazure-functions-host-python3.13-worker

    < 4.1048.200-r1

  • chainguardbarman

    < 3.16.2-r1

  • chainguardbarman-cloudnative-pg

    < 3.16.2-r1

  • chainguardconfluent-docker-utils

    < 0.0.162-r4

  • chainguarddask-gateway

    < 2025.4.0-r7

  • chainguarddask-gateway-server

    < 2025.4.0-r7

  • chainguarddask-kubernetes

    < 2025.7.0-r2

  • chainguarddatadog-agent-7.71

    < 7.71.2-r22

  • chainguarddatadog-agent-7.71-core-integrations

    < 7.71.2-r22 | all

  • chainguarddatadog-agent-7.72

    < 7.72.4-r22

  • chainguarddatadog-agent-7.72-core-integrations

    < 7.72.4-r22

  • chainguarddatadog-agent-7.73

    < 7.73.3-r13

  • chainguarddatadog-agent-7.73-core-integrations

    < 7.73.3-r13

  • chainguarddatadog-agent-7.74

    < 7.74.1-r15

  • chainguarddatadog-agent-7.74-core-integrations

    < 7.74.1-r15

  • chainguarddatadog-agent-7.75

    < 7.75.4-r7

  • chainguarddatadog-agent-7.75-core-integrations

    < 7.75.4-r7

  • chainguarddatadog-agent-7.76

    < 7.76.3-r15 | < 7.76.3-r41 | all

  • chainguarddatadog-agent-7.76-core-integrations

    < 7.76.3-r15

  • chainguarddatadog-agent-7.77

    < 7.77.3-r6

  • chainguarddatadog-agent-7.77-core-integrations

    < 7.77.3-r6

  • chainguarddatadog-agent-fips-7.71

    < 7.71.2-r15

  • chainguarddatadog-agent-fips-7.71-core-integrations

    all | < 7.71.2-r15

  • chainguarddatadog-agent-fips-7.72

    < 7.72.4-r15 | < 7.72.4-r14

  • chainguarddatadog-agent-fips-7.72-core-integrations

    < 7.72.4-r14 | < 7.72.4-r15

  • chainguarddatadog-agent-fips-7.73

    < 7.73.3-r12

Showing first 50 affected entries in server-rendered view.

References (37)