shield
Security update for python-urllib3
SUSE-SLE-Module-Public-Cloud-12-2026-1412
This update for python-urllib3 fixes the following issues: Security issues: - CVE-2025-66418: resource exhaustion via unbounded number of links in the decompression chain (bsc#1254866). - CVE-2025-66471: excessive resource consumption via decompression of highly compressed data in Streaming API (bsc#1254867). - CVE-2026-21441: excessive resource consumption during decompression of data in HTTP redirect responses (bsc#1256331). Non-security issues: - Disabled response decompression with brotli due to missing brotli feature (jsc#PED-15380).
-
Release DateApr 16 2026
-
References
-
Typesecurity
-
Severitymoderate
cloud_download Downloads
Public Cloud Module 12 s390x
-
Packagespython-urllib3
HTTP library with thread-safe connection pooling, file post, and morepython3-urllib31.25.10-3.48.4 lock rpm lock src
HTTP library with thread-safe connection pooling, file post, and more1.25.10-3.48.4 lock rpm
Public Cloud Module 12 ppc64le
-
Packagespython-urllib3
HTTP library with thread-safe connection pooling, file post, and morepython3-urllib31.25.10-3.48.4 lock rpm lock src
HTTP library with thread-safe connection pooling, file post, and more1.25.10-3.48.4 lock rpm
Public Cloud Module 12 aarch64
-
Packagespython-urllib3
HTTP library with thread-safe connection pooling, file post, and morepython3-urllib31.25.10-3.48.4 lock rpm lock src
HTTP library with thread-safe connection pooling, file post, and more1.25.10-3.48.4 lock rpm
Public Cloud Module 12 x86_64
-
Packagespython-urllib3
HTTP library with thread-safe connection pooling, file post, and morepython3-urllib31.25.10-3.48.4 lock rpm lock src
HTTP library with thread-safe connection pooling, file post, and more1.25.10-3.48.4 lock rpm