CVE-2025-66418: urllib3 allows an unbounded number of links in the decompression chain

Overview

Severity
N/A
Exploit Status
Not Exploited
Patch Tuesday
2025-Dec
Released
2025-12-10
Last Updated
2026-02-18
EPSS Score
0.03% (percentile: 9.8%)

Affected Products (5)

Open Source Software

  • cbl2 python-urllib3 1.26.19-2 on CBL Mariner 2.0
  • cbl2 python-virtualenv 20.26.6-2 on CBL Mariner 2.0

Mariner

  • azl3 tensorflow 2.16.1-9 on Azure Linux 3.0
  • azl3 python-urllib3 2.0.7-2 on Azure Linux 3.0

Other

  • 20890-17086

Revision History

  • 2025-12-10: Information published.
  • 2025-12-11: Information published.
  • 2025-12-16: Information published.
  • 2025-12-17: Information published.
  • 2025-12-23: Information published.
  • 2026-02-18: Information published.