Summary
NIOExtras: NIOHTTPRequestDecompressor ratio limit bypass via inflated Content-Length
References
Related vulnerabilities
All Supply chain →- MEDIUMGHSA-6PR9-RP53-2PMC
vLLM: OOM Denial of Service via Audio Decompression Bomb
- MEDIUMGHSA-JQPW-QWW5-CJ4C
n8n: Denial of Service via ZIP decompression in webhook workflow
- MEDIUMGHSA-WJQC-6W8F-H24C
pypdf: Manipulated XMP metadata streams can exhaust RAM
- MEDIUMGHSA-563Q-J3CM-6JXM
Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature
- HIGHGHSA-5W86-C3RQ-VJJ7
Netty: Unbounded pre-allocation in RedisArrayAggregator from RESP array length
- HIGHGHSA-4GRM-H2QV-H6W6
Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion