CVE-2026-59939 @ Bullseye
Status
new
Priority
0.62
Match score
4.0
Risk
DoS
Remote
CVSS
7.5 HIGH
Reason
cpe: httplib2; pkgs: httplib2; version: in-range: python3-httplib2-0.18.1-3, httplib2-0.18.1-3; debian:bullseye python-httplib2 open; risk:dos
Created
2026-08-21T10:16:27Z
Updated
2026-08-22T10:15:32Z
Package interrogation (copy)
Run on the host — click to copy a command. Debian/apt
| Package | Commands |
|---|---|
| python3-httplib2-0.18.1-3 | |
| httplib2-0.18.1-3 |
Inventory lookup
Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.
Suggestions: python3-httplib2 · httplib2
Related CVE (same fix)
Point this ticket’s CVE at a higher-priority / same-fix primary so you only triage one.
Host OS / kernel
OS
Debian GNU/Linux 11 (bullseye)
(11)
· debian
Arch
x86_64
kernel_release
uname -r → 5.10.0-45-amd64kernel_version
uname -v → #1 SMP Debian 5.10.259-1 (2026-07-02)For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.
Same CVE on other hosts
Open the ticket for this CVE on another system.
| System | Status | Priority | Updated | |
|---|---|---|---|---|
| Silk | new | 4.0 | 2026-08-22T10:15:32Z | Open |
| Matrix | new | 1.75 | 2026-08-22T10:15:32Z | Open |
Description
httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allowing a malicious or compromised HTTP server to return a small compressed payload that expands to an arbitrarily large size in memory and causes MemoryError or OOM-kill in the client process. This issue is fixed in version 0.32.0.
Update status
Add note only
References
- https://github.com/httplib2/httplib2/commit/87581ad6cf752fe3da2090c59058261d2d00a427
- https://github.com/httplib2/httplib2/releases/tag/v0.32.0
- https://github.com/httplib2/httplib2/security/advisories/GHSA-j5g9-f88f-gfj3
- https://lists.debian.org/debian-lts-announce/2026/08/msg00039.html
- https://github.com/httplib2/httplib2/security/advisories/GHSA-j5g9-f88f-gfj3
NVD: CVE-2026-59939