urllib3-future is vulnerable to Decompression-bomb
89
High Risk
Affected versions of this package may decompress entire HTTP redirect response bodies even when using the streaming API with preload_content=False, ignoring read limits. It can lead to excessive CPU and memory usage. An attacker can exploit this by hosting a redirect response containing a compressed decompression bomb, causing the client to automatically decompress massive data before any reads occur, resulting in denial of service.
You are affected if you are using a version that falls within the vulnerable range.
urllib3-future is vulnerable to Decompression-bomb in versions 1.2.0 - 2.15.901.
Upgrade the urllib3-future library to the patch version or disable redirects for requests to untrusted sources by setting redirect=False.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant