Untriaged
Permalink
CVE-2026-40036
7.5 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): NONE
- Integrity impact (I): NONE
- Availability impact (A): HIGH
Unfurl < 2026.04 - Denial of Service via Unbounded zlib Decompression
Unfurl before 2026.04 contains an unbounded zlib decompression vulnerability in parse_compressed.py that allows remote attackers to cause denial of service. Attackers can submit highly compressed payloads via URL parameters to the /json/visjs endpoint that expand to gigabytes, exhausting server memory and crashing the service.
References
-
GHSA Advisory GHSA-h5qv-qjv4-pc5m vendor-advisory
-
https://www.vulncheck.com/advisories/dfir-unfurl-denial-of-service-via-unbounde… third-party-advisory
Affected products
dfir-unfurl
- <2026.04
Package maintainers
-
@figsoda figsoda <figsoda@pm.me>