THREAT OPS › Threat News › [GHSA] GHSA-655f-mp8p-96gv (high) — Req vulnerable to unbounded archive/compression extraction triggered by response content-type
[GHSA] GHSA-655f-mp8p-96gv (high) — Req vulnerable to unbounded archive/compression extraction triggered by response content-type
GHSA-655f-mp8p-96gv Severity: high CVE: CVE-2026-49755
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
### Summary
Req's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied `content-type` (or URL extension) and materialises the full decompressed contents in memory with no size cap. An attacker who contro
MITRE ATT&CK techniques
- CompressionT1027.015
Indicators of compromise
- CVE-2026-49755cve
Original source: https://github.com/advisories/GHSA-655f-mp8p-96gv