PT-2026-65455 · Lookyloo · Lookyloo
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Lookyloo (affected versions not specified)
Description
Lookyloo fails to enforce limits on the decompressed size of uploaded capture archives and compressed HAR files. An attacker can submit a specially crafted ZIP, gzip, or zlib-compressed capture containing data that expands to an excessive size during processing. Since the application decompresses this content directly in memory without limiting the output size, it can lead to memory exhaustion, termination of web or worker processes, or complete instance unavailability. This issue affects full capture archive imports and API submissions containing gzip-compressed HAR data. Repeated exploitation may result in a persistent denial-of-service condition, which is a state where a service is unavailable to its intended users, until the affected processes or instance are restarted.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lookyloo