PT-2026-96285 · Pypi · Zapros

CVE-2026-61652

·

Published

2026-09-21

·

Updated

2026-09-29

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Zapros versions prior to 0.14.0
Description A denial of service via memory exhaustion occurs when streaming compressed responses. The decoder ignores the memory bound set by the chunk size, whether specified explicitly via iter bytes(chunk size=...) or using the default value. Consequently, a chunk can exceed the requested size, allowing a single compressed response to overflow memory.
Recommendations Update to version 0.14.0. Read the compressed body using Response.iter raw() or Response.async iter raw() to bypass built-in decoders and perform decompression manually with an explicit output-size bound, such as zlib's max length. Send Accept-Encoding: identity to disable response compression. Avoid decoding response bodies from untrusted servers.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61652
GHSA-6CP7-3M3C-5X5C

Affected Products

Zapros