THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-g4w2-6h2r-3m3w (high) — http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoS

[GHSA] GHSA-g4w2-6h2r-3m3w (high) — http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoS

medgithub_advisoriesPublished 2026-08-17

GHSA-g4w2-6h2r-3m3w Severity: high CVE: CVE-2026-53659

http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoS

### Impact

`ServerFilters.GZip` and `RequestFilters.GunZip` (and the underlying `Gzip` functions used to decompress request bodies) did not impose any cap on the decompressed size. A small malicious gzip-encoded request body

Indicators of compromise

Original source: https://github.com/advisories/GHSA-g4w2-6h2r-3m3w