<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T23:42:20.881969+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-374812</id>
    <title>EUVD-2026-374812</title>
    <updated>2026-10-03T23:42:21.000450+00:00</updated>
    <content>EUVD-2026-374812</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-374812"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-40036</id>
    <title>fkie_cve-2026-40036</title>
    <updated>2026-10-03T23:42:21.000492+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Unfurl before 2026.04 contains an unbounded zlib decompression vulnerability in parse_compressed.py that allows remote attackers to cause denial of service. Attackers can submit highly compressed payloads via URL parameters to the /json/visjs endpoint that expand to gigabytes, exhausting server memory and crashing the service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-40036"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h5qv-qjv4-pc5m</id>
    <title>GHSA-h5qv-qjv4-pc5m — Unfurl's unbounded zlib decompression allows decompression bomb DoS</title>
    <updated>2026-10-03T23:42:21.000528+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: dfir-unfurl</p>
<p>### Summary
The compressed data parser uses `zlib.decompress()` without a maximum output size. A small, highly compressed payload can expand to a very large output, causing memory exhaustion and denial of service.</p>
<p>### Details
- `unfurl/parsers/parse_compressed.py` calls `zlib.decompress(decoded)` with no size limit.
- Inputs are accepted from URL components that match base64 patterns.
- Highly compressible payloads can expand orders of magnitude larger than their compressed size.</p>
<p>### PoC
1. Generate a payload with `security_poc/poc_decompression_bomb.py --generate-only`.
2. The script creates a base64-encoded zlib payload embedded in a URL.
3. Submitting the URL to `/json/visjs` can cause the server to allocate large amounts of memory.
4. The script includes a `--test` mode but warns it can crash the service.</p>
<p>### PoC Script
```python
#!/usr/bin/env python3
"""
Unfurl Decompression Bomb Proof of Concept
==========================================</p>
<p>This PoC demonstrates a Denial of Service vulnerability in Unfurl's
compressed data parsing. The zlib.decompress() call has no size limits,
allowing an attacker to submit small payloads that expand to gigabytes.</p>
<p>Vulnerability Location:
- parse_compressed.py:81-82:
    inflated_bytes = zlib.decompress(decoded)  # No maxsize parameter</p>
<p>Attack Impact:
- Memory exhaustion
- Service crash
- Resource consumption (cloud cost attacks)</p>
<p>Usage:
    python poc_decompression_bomb.py [--target URL] [--size SIZE_MB]
"""</p>
<p>import argparse
import…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h5qv-qjv4-pc5m"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-1294</id>
    <title>PYSEC-2026-1294 — Unfurl's unbounded zlib decompression allows decompression bomb DoS</title>
    <updated>2026-10-03T23:42:21.000635+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: dfir-unfurl</p>
<p>### Summary
The compressed data parser uses `zlib.decompress()` without a maximum output size. A small, highly compressed payload can expand to a very large output, causing memory exhaustion and denial of service.</p>
<p>### Details
- `unfurl/parsers/parse_compressed.py` calls `zlib.decompress(decoded)` with no size limit.
- Inputs are accepted from URL components that match base64 patterns.
- Highly compressible payloads can expand orders of magnitude larger than their compressed size.</p>
<p>### PoC
1. Generate a payload with `security_poc/poc_decompression_bomb.py --generate-only`.
2. The script creates a base64-encoded zlib payload embedded in a URL.
3. Submitting the URL to `/json/visjs` can cause the server to allocate large amounts of memory.
4. The script includes a `--test` mode but warns it can crash the service.</p>
<p>### PoC Script
```python
#!/usr/bin/env python3
"""
Unfurl Decompression Bomb Proof of Concept
==========================================</p>
<p>This PoC demonstrates a Denial of Service vulnerability in Unfurl's
compressed data parsing. The zlib.decompress() call has no size limits,
allowing an attacker to submit small payloads that expand to gigabytes.</p>
<p>Vulnerability Location:
- parse_compressed.py:81-82:
    inflated_bytes = zlib.decompress(decoded)  # No maxsize parameter</p>
<p>Attack Impact:
- Memory exhaustion
- Service crash
- Resource consumption (cloud cost attacks)</p>
<p>Usage:
    python poc_decompression_bomb.py [--target URL] [--size SIZE_MB]
"""</p>
<p>import argparse
import…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-1294"/>
  </entry>
</feed>
