------------------------------------------------------------------------- Debian LTS Advisory DLA-4747-1 [email protected] https://www.debian.org/lts/security/ Emmanuel Arias August 20, 2026 https://wiki.debian.org/LTS -------------------------------------------------------------------------
Package : python-httplib2
Version : 0.18.1-3+deb11u1
CVE ID : CVE-2021-21240 CVE-2026-59939
Debian Bug : 982738
Two vulnerabilities were discovered in python-httplib2, a comprehensive Python
HTTP
client library:
CVE-2021-21240
A malicious server which responds with long series of '\xa0' characters in
the 'www-authenticate' header may cause Denial of Service (CPU burn while
parsing header) of the httplib2 client accessing said server
CVE-2026-59939
Unbounded decompression of HTTP response bodies encoded with gzip or deflate
Content-Encoding could result in denial of service.
For Debian 11 bullseye, these problems have been fixed in version
0.18.1-3+deb11u1.
We recommend that you upgrade your python-httplib2 package.
For the detailed security status of python-httplib2 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/python-httplib2
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
signature.asc
Description: PGP signature
