|
|
Log in / Subscribe / Register

Ubuntu alert USN-7955-1 (python-urllib3)

From:  noreply+usn-bot@canonical.com
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-7955-1] urllib3 vulnerability
Date:  Mon, 12 Jan 2026 15:56:27 +0000
Message-ID:  <E1vfKHL-0005v5-Sa@lists.ubuntu.com>

========================================================================== Ubuntu Security Notice USN-7955-1 January 12, 2026 python-urllib3 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 25.04 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: urllib3 could be made to use excessive resources if it received specially crafted network traffic. Software Description: - python-urllib3: HTTP library with thread-safe connection pooling Details: It was discovered that urllib3 incorrectly handled decompression during HTTP redirects. An attacker could possibly use this issue to cause urllib3 to use excessive resources, causing a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 python3-urllib3 2.3.0-3ubuntu0.2 Ubuntu 25.04 python3-urllib3 2.3.0-2ubuntu0.3 Ubuntu 24.04 LTS python3-urllib3 2.0.7-1ubuntu0.4 Ubuntu 22.04 LTS python3-urllib3 1.26.5-1~exp1ubuntu0.5 Ubuntu 20.04 LTS python3-urllib3 1.25.8-2ubuntu0.4+esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7955-1 CVE-2026-21441 Package Information: https://launchpad.net/ubuntu/+source/python-urllib3/2.3.0... https://launchpad.net/ubuntu/+source/python-urllib3/2.3.0... https://launchpad.net/ubuntu/+source/python-urllib3/2.0.7... https://launchpad.net/ubuntu/+source/python-urllib3/1.26....


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmllGXwACgkQcpJm3tlz hgG8yA//VZAW2BOfLZ/+PvHWVoyhGGlhy9+O1uty4D543hnhGudsSk84+YLGK0zP Yc5WS6hR97IhEiscCVbbqcd75424FXDcxqcgJfCDkU3yT4ucLI3QqG3cbQbt87sD xLuyAyNXd7Wk3GkHJa4eFI+rT5EWxgyO0455FY2dfu50I6Ca8IPM7ejwct38qwcV QTspxVaqmXPChgIAYEcqp7huJOkS/HyL913ndA9c78g4oJaGTTqh5poeOmZLlHol dxfF1ogfftq3XdpSKM5n2IUY59RKCN1bgGbJJads2ZECwn75f6JfvfPAg76hhXkH WoHg/3GHQRbWoZBB2mU4/lraPnPpqBCiQ0W5Tc7NIEpGsbUevdhQYOgloHvIx2AB osWNTIw1liaucQA8il5OwsgOSxAhi9QsuOpkBjBZ2Nh8216pfAzGwQPpohM56WDO goizLjTihXvl6Eseey64TIc5LCgO91vfxJK0wdjj+rq6rpe6btxcl/13ztG8WQBI EFa0OxxkLtS8t2hnKvXtM6SN+12iAVrTOhlGHlUZMg6iqjIoGEGjWO4pKVcpBtDD pBKxuejSU7IXWFmP1rTf+LV+vqHAcaKI3+8lzj51cunoX8Tj8IZ8IatndyPFgaeu OgzJhAOCZJp/fgB1f3SfJYz/5ZvOS/Iy3X9YZBgfG7Q9EqxRsh4= =MMji -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds