Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-59939

34
FAUCET Score

httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allowing a malicious or compromised HTTP server to return a small compressed payload that expands to an arbitrarily large size in memory and causes MemoryError or OOM-kill in the client process. This issue is fixed in version 0.32.0.

First published: Jul 8, 2026Last modified: Jul 8, 2026

Impacted Technologies

VendorProductVersion(s)CPE
< 0.32.0CPE matchmatch criteria
cpe:2.3:a:httplib2_project:httplib2:*:*:*:*:*:python:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.41%
Probability of exploitation in next 30 days
EPSS Percentile
33.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0041 is in the 13th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: httplib2Fixed in: 0.32.0
ubuntupatch availablevia ubuntu_usn
Product: python-httplib2 (jammy)Fixed in: 0.20.2-2ubuntu0.1
ubuntupatch availablevia ubuntu_usn
Product: python-httplib2 (noble)Fixed in: 0.20.4-3ubuntu0.1
ubuntupatch availablevia ubuntu_usn
Product: python-httplib2 (resolute)Fixed in: 0.22.0-1ubuntu0.1

Vendor Advisories (2)

pipGHSA-j5g9-f88f-gfj3high

httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling

Jul 24, 2026
ubuntuUSN-8537-1

httplib2 vulnerability

Jul 14, 2026

References

github.com / httplib2/httplib2/commit/87581ad6cf752fe3da2090c59058261d2d00a427
Patch
github.com / httplib2/httplib2/releases/tag/v0.32.0
Release Notes
github.com / httplib2/httplib2/security/advisories/GHSA-j5g9-f88f-gfj3
ExploitVendor Advisory