PT-2026-96285 · Pypi · Zapros
CVE-2026-61652
·
Published
2026-09-21
·
Updated
2026-09-29
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Zapros versions prior to 0.14.0
Description
A denial of service via memory exhaustion occurs when streaming compressed responses. The decoder ignores the memory bound set by the chunk size, whether specified explicitly via
iter bytes(chunk size=...) or using the default value. Consequently, a chunk can exceed the requested size, allowing a single compressed response to overflow memory.Recommendations
Update to version 0.14.0.
Read the compressed body using
Response.iter raw() or Response.async iter raw() to bypass built-in decoders and perform decompression manually with an explicit output-size bound, such as zlib's max length.
Send Accept-Encoding: identity to disable response compression.
Avoid decoding response bodies from untrusted servers.Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zapros