VDB
GCVE-VVD-MAGEIA-2026-11
GCVE-VVD-MAGEIA-2026-11
Advisory Published
urllib3 allows an unbounded number of links in the decompression chain.
(CVE-2025-66418)
urllib3 vulnerable to decompression-bomb safeguard bypass when following
HTTP redirects (streaming API). (CVE-2026-21441)
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | python-urllib3 | 0 (affected), 1.26.20-1.2.mga9 (unaffected), 0 (affected), 1.26.20-1.2.mga9 (unaffected) | — |
| Mageia | yt-dlp | 0 (affected), 2026.02.04-1.mga9 (unaffected) | — |
References
Updated yt-dlp packages fix bugs
advisory
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.