Improper handling of highly compressed data in httplib2 - CVE-2026-59939

 

Improper handling of highly compressed data in httplib2 - CVE-2026-59939

Published: June 29, 2026


Vulnerability identifier: #VU135769
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-59939
CWE-ID: CWE-409
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper handling of highly compressed data in the _decompressContent() function when processing HTTP responses with Content-Encoding: gzip or deflate. A remote attacker can send a specially crafted compressed HTTP response to cause a denial of service.

The issue is triggered automatically during httplib2.Http().request() and requires no user interaction.


Affected software

httplib2
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Public Cloud Module
openSUSE Leap
Ubuntu
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
python-httplib2 (Ubuntu package)
python-httplib2 (Debian package)
python311-httplib2
fence-agents-aliyun-debuginfo (Red Hat package)
fence-agents-all (Red Hat package)
fence-agents-debuginfo (Red Hat package)
fence-agents-debugsource (Red Hat package)
fence-agents-kdump-debuginfo (Red Hat package)
fence-agents-kubevirt-debuginfo (Red Hat package)
fence-agents-aliyun (Red Hat package)
fence-agents (Red Hat package)

How to mitigate CVE-2026-59939

Install security update from vendor's website.

httplib2 - update to 0.32.0
python-httplib2 (Ubuntu package) - addressed in versions 0.20.2-2ubuntu0.1, 0.20.4-3ubuntu0.1, 0.22.0-1ubuntu0.1
python-httplib2 (Debian package) - update to 0.22.0-1+deb13u1
python311-httplib2 - update to 0.22.0-150400.10.7.1
fence-agents-aliyun-debuginfo (Red Hat package) - update to 4.2.1-65.el8_4.30
fence-agents-all (Red Hat package) - update to 4.2.1-65.el8_4.30
fence-agents-debuginfo (Red Hat package) - update to 4.2.1-65.el8_4.30
fence-agents-debugsource (Red Hat package) - update to 4.2.1-65.el8_4.30
fence-agents-kdump-debuginfo (Red Hat package) - update to 4.2.1-65.el8_4.30
fence-agents-kubevirt-debuginfo (Red Hat package) - update to 4.2.1-65.el8_4.30
fence-agents-aliyun (Red Hat package) - update to 4.2.1-65.el8_4.30
fence-agents (Red Hat package) - addressed in versions 4.2.1-89.el8_6.24, 4.2.1-112.el8_8.19, 4.10.0-62.el9_4.27, 4.10.0-86.el9_6.19, 4.16.0-5.el10_0.12, 4.16.0-21.el10_2.5

External References

Related Security Bulletins