shield Security update for python-urllib3
SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3397


This update for python-urllib3 fixes the following issue - CVE-2026-9375: decompression bomb bypass in the streaming API when using Brotli support can lead to a denial of service (bsc#1268683).

  • Release Date
    Jul 28 2026
  • References
    Bugzilla: 1268683
    CVEs: CVE-2026-9375
  • Type
    security
  • Severity
    moderate

cloud_download Downloads

Public Cloud Module 15.4 ppc64le
  • Packages
    python-urllib3
    HTTP library with thread-safe connection pooling, file post, and more
    2.0.7-150400.7.33.1 lock src
    python311-urllib3
    HTTP library with thread-safe connection pooling, file post, and more
    2.0.7-150400.7.33.1 lock rpm
Public Cloud Module 15.4 s390x
  • Packages
    python-urllib3
    HTTP library with thread-safe connection pooling, file post, and more
    2.0.7-150400.7.33.1 lock src
    python311-urllib3
    HTTP library with thread-safe connection pooling, file post, and more
    2.0.7-150400.7.33.1 lock rpm
Public Cloud Module 15.4 aarch64
  • Packages
    python-urllib3
    HTTP library with thread-safe connection pooling, file post, and more
    2.0.7-150400.7.33.1 lock src
    python311-urllib3
    HTTP library with thread-safe connection pooling, file post, and more
    2.0.7-150400.7.33.1 lock rpm
Public Cloud Module 15.4 x86_64
  • Packages
    python-urllib3
    HTTP library with thread-safe connection pooling, file post, and more
    2.0.7-150400.7.33.1 lock src
    python311-urllib3
    HTTP library with thread-safe connection pooling, file post, and more
    2.0.7-150400.7.33.1 lock rpm