CVE Tracker

CVE-2026-59939 @ Silk

Status
new
Priority
4.0
Match score
4.0
Risk
DoS Remote
CVSS
7.5 HIGH
Reason
cpe: httplib2; pkgs: httplib2; version: in-range: python3-httplib2-0.20.4-3+deb12u1, httplib2-0.20.4-3+deb12u1; debian:bookworm python-httplib2 open; risk:dos
Created
2026-08-21T10:16:27Z
Updated
2026-08-22T10:15:32Z

Package interrogation (copy)

Run on the host — click to copy a command. Debian/apt

PackageCommands
python3-httplib2-0.20.4-3+deb12u1
httplib2-0.20.4-3+deb12u1

Inventory lookup

Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.

Clear

Suggestions: python3-httplib2 · httplib2

SystemMatchesTicket for CVE-2026-59939
Bullseye python3-httplib2 0.18.1-3 new open
Matrix python3-httplib2 0.20.4-3 new open
Silk python3-httplib2 0.20.4-3+deb12u1 new open

Related CVE (same fix)

Point this ticket’s CVE at a higher-priority / same-fix primary so you only triage one.

Host OS / kernel

OS
Debian GNU/Linux 12 (bookworm) (12) · debian
Arch
x86_64
kernel_release
uname -r → 6.1.0-52-amd64
kernel_version
uname -v → #1 SMP PREEMPT_DYNAMIC Debian 6.1.180-1 (2026-08-03)

For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.

Same CVE on other hosts

Open the ticket for this CVE on another system.

System Status Priority Updated
Matrix new 1.75 2026-08-22T10:15:32Z Open
Bullseye new 0.62 2026-08-22T10:15:32Z Open

Description

httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allowing a malicious or compromised HTTP server to return a small compressed payload that expands to an arbitrarily large size in memory and causes MemoryError or OOM-kill in the client process. This issue is fixed in version 0.32.0.

Update status

Also apply to other systems with this CVE:

Add note only

Also add note on:

References

NVD: CVE-2026-59939