Improper handling of highly compressed data in httplib2 - CVE-2026-59939
Published: June 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of highly compressed data in the _decompressContent() function when processing HTTP responses with Content-Encoding: gzip or deflate. A remote attacker can send a specially crafted compressed HTTP response to cause a denial of service.
The issue is triggered automatically during httplib2.Http().request() and requires no user interaction.
Affected software
Debian Linux
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Ubuntu
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
python-httplib2 (Ubuntu package)
python-httplib2 (Debian package)
fence-agents-aliyun-debuginfo (Red Hat package)
fence-agents-all (Red Hat package)
fence-agents-debuginfo (Red Hat package)
fence-agents-debugsource (Red Hat package)
fence-agents-kdump-debuginfo (Red Hat package)
fence-agents-kubevirt-debuginfo (Red Hat package)
fence-agents-aliyun (Red Hat package)
fence-agents (Red Hat package)
How to mitigate CVE-2026-59939
python-httplib2 (Ubuntu package) - addressed in versions 0.20.2-2ubuntu0.1, 0.20.4-3ubuntu0.1, 0.22.0-1ubuntu0.1
python-httplib2 (Debian package) - update to 0.22.0-1+deb13u1
fence-agents-aliyun-debuginfo (Red Hat package) - update to 4.2.1-65.el8_4.30
fence-agents-all (Red Hat package) - update to 4.2.1-65.el8_4.30
fence-agents-debuginfo (Red Hat package) - update to 4.2.1-65.el8_4.30
fence-agents-debugsource (Red Hat package) - update to 4.2.1-65.el8_4.30
fence-agents-kdump-debuginfo (Red Hat package) - update to 4.2.1-65.el8_4.30
fence-agents-kubevirt-debuginfo (Red Hat package) - update to 4.2.1-65.el8_4.30
fence-agents-aliyun (Red Hat package) - update to 4.2.1-65.el8_4.30
fence-agents (Red Hat package) - addressed in versions 4.2.1-89.el8_6.24, 4.2.1-112.el8_8.19, 4.10.0-62.el9_4.27, 4.10.0-86.el9_6.19, 4.16.0-5.el10_0.12, 4.16.0-21.el10_2.5
External References
Related Security Bulletins
- Improper handling of highly compressed data in httplib2
- Ubuntu update for python-httplib2
- Red Hat Enterprise Linux 10 update for fence-agents
- Red Hat Enterprise Linux 8 update for fence-agents
- Red Hat Enterprise Linux 8 update for fence-agents
- Red Hat Enterprise Linux 8 update for fence-agents
- Red Hat Enterprise Linux 10 update for fence-agents
- Red Hat Enterprise Linux 9 update for fence-agents
- Red Hat Enterprise Linux 9 update for fence-agents
- Debian update for python-httplib2