THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-655f-mp8p-96gv (high) — Req vulnerable to unbounded archive/compression extraction triggered by response content-type

[GHSA] GHSA-655f-mp8p-96gv (high) — Req vulnerable to unbounded archive/compression extraction triggered by response content-type

medgithub_advisoriesPublished 2026-07-29

GHSA-655f-mp8p-96gv Severity: high CVE: CVE-2026-49755

Req vulnerable to unbounded archive/compression extraction triggered by response content-type

### Summary

Req's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied `content-type` (or URL extension) and materialises the full decompressed contents in memory with no size cap. An attacker who contro

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-655f-mp8p-96gv