VDB

GCVE-VVD-MAGEIA-2026-11

GCVE-VVD-MAGEIA-2026-11
Advisory Published
Vulnetix · Advisory published February 6, 2026
urllib3 allows an unbounded number of links in the decompression chain. (CVE-2025-66418) urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API). (CVE-2026-21441)

Affected Products

VendorProductVersionsPlatforms
Mageiapython-urllib30 (affected), 1.26.20-1.2.mga9 (unaffected), 0 (affected), 1.26.20-1.2.mga9 (unaffected)
Mageiayt-dlp0 (affected), 2026.02.04-1.mga9 (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›