SUSE Python-httplib2 OOM Vulnerability Disclosed

SUSE Python-httplib2 OOM Vulnerability Disclosed

First seen 1 Sep 2026, 12:00 UTC Linuxsecurity 63.0

Article Content

Browse articles
ThreatCluster

An important vulnerability (CVE-2026-59939) has been identified in the SUSE python-httplib2 package, which can lead to an Out Of Memory (OOM) kill in client processes. This issue arises from unbounded decompression of HTTP response bodies using gzip or deflate encoding when connecting to compromised HTTP servers. Affected systems include SUSE Linux Enterprise Server and openSUSE Leap versions 15.4 and 15-SP4/15-SP5. The vulnerability was published on July 8, 2026, and has a CVSS score of 7.5, indicating a high severity level. Users are advised to apply the latest patches using SUSE's recommended installation methods. The patch addresses the OOM risk and is critical for maintaining system stability and security.

Key Points: • CVE-2026-59939 poses an OOM risk in python-httplib2. • Affected systems include SUSE Linux Enterprise and openSUSE Leap. • Immediate patching is recommended to mitigate the vulnerability.

Timeline

2026-05-13
CVE-2026-7168 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-13
CVE-2026-5773 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-03
CVE-2026-8926 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-08
CVE-2026-59939 published
SUSE disclosed a vulnerability in python-httplib2 that can lead to OOM-kill in client processes.
Linuxsecurity
2026-08-31
Patch released for CVE-2026-59939
SUSE released an important update to address the OOM vulnerability in python-httplib2.
Linuxsecurity