PT-2026-65455 · Lookyloo · Lookyloo

·

CVE-2026-66913

·

Published

2026-07-28

·

Updated

2026-07-28

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Lookyloo (affected versions not specified)
Description Lookyloo fails to enforce limits on the decompressed size of uploaded capture archives and compressed HAR files. An attacker can submit a specially crafted ZIP, gzip, or zlib-compressed capture containing data that expands to an excessive size during processing. Since the application decompresses this content directly in memory without limiting the output size, it can lead to memory exhaustion, termination of web or worker processes, or complete instance unavailability. This issue affects full capture archive imports and API submissions containing gzip-compressed HAR data. Repeated exploitation may result in a persistent denial-of-service condition, which is a state where a service is unavailable to its intended users, until the affected processes or instance are restarted.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66913

Affected Products

Lookyloo