PT-2026-70893 · Ffuf · Ffuf

CVE-2026-73232

·

Published

2026-08-11

·

Updated

2026-09-10

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ffuf versions prior to 2.2.0
Description A malicious target server can trigger an out-of-memory denial of service. This occurs because the response size guard in the pkg/runner/simple.go file only verifies the compressed Content-Length, whereas the io.ReadAll() function reads gzip, brotli, deflate, transparently decompressed, or chunked response bodies without a bound on the decompressed size.
Recommendations Update to version 2.2.0.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73232
GHSA-JCVH-XF52-2CWM
GO-2026-6369

Affected Products

Ffuf