THREAT OPS › Threat News › [GHSA] GHSA-g4w2-6h2r-3m3w (high) — http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoS
[GHSA] GHSA-g4w2-6h2r-3m3w (high) — http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoS
GHSA-g4w2-6h2r-3m3w Severity: high CVE: CVE-2026-53659
http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoS
### Impact
`ServerFilters.GZip` and `RequestFilters.GunZip` (and the underlying `Gzip` functions used to decompress request bodies) did not impose any cap on the decompressed size. A small malicious gzip-encoded request body
Indicators of compromise
- CVE-2026-53659cve
- enterprise@http4k.orgemail
- 6.49.0.0ipv4
- 5.42.0.0ipv4
- 4.51.0.0ipv4
Original source: https://github.com/advisories/GHSA-g4w2-6h2r-3m3w