generated from amazon-archives/__template_Apache-2.0
-
Notifications
You must be signed in to change notification settings - Fork 115
Open
Description
CVE Details
| CVE ID | Severity | Affected Package | Installed Version | Fixed Version | Date Published | Date of Scan |
|---|---|---|---|---|---|---|
| CVE-2025-66418 | HIGH |
urllib3 |
1.26.19 |
2.6.0 |
2025-12-05T16:15:51.053Z |
2025-12-06T10:19:10.048869941Z |
Affected Docker Images
| Image Name | SHA |
|---|---|
public.ecr.aws/lambda/python:latest |
public.ecr.aws/lambda/python@sha256:42fd4356bf50655e7fff84abd2b7da8ac83536e363bb15c360a07f1781198e15 |
public.ecr.aws/lambda/python:3.14 |
public.ecr.aws/lambda/python@sha256:6ac4753bf6baf5a2df0cde8a6f6e9a351742cfdadb7664ca51f68558412bb716 |
public.ecr.aws/lambda/python:3.13 |
public.ecr.aws/lambda/python@sha256:42fd4356bf50655e7fff84abd2b7da8ac83536e363bb15c360a07f1781198e15 |
public.ecr.aws/lambda/python:3.12 |
public.ecr.aws/lambda/python@sha256:418b60ecd5be70360a062d2f369807fe5e2c732e5e8f3d57c6cc0381b51fc89f |
public.ecr.aws/lambda/python:3.11 |
public.ecr.aws/lambda/python@sha256:96c69e2eda46eed5a3da62d44fcba42a38fe4e0c7bc6fd300c5b84800ad98387 |
public.ecr.aws/lambda/python:3.10 |
public.ecr.aws/lambda/python@sha256:6d5b6f61c363cadb295c164ec80cd743a268bd70e0e9d5bb1f4163b0db1e8b16 |
public.ecr.aws/lambda/python:3.9 |
public.ecr.aws/lambda/python@sha256:406c0a7733c40f59855296d97b864d4c09524ba60b4e367a8c98c3d251050f3d |
Description
urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimited number of compression steps leading to high CPU usage and massive memory allocation for the decompressed data. This vulnerability is fixed in 2.6.0.
Remediation Steps
- Update the affected package
urllib3from version1.26.19to2.6.0.
About this issue
- This issue may not contain all the information about the CVE nor the images it affects.
- This issue will not be updated with new information and the list of affected images may have changed since the creation of this issue.
- For more, visit Lambda Watchdog.
- This issue was created automatically by Lambda Watchdog.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels