THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-jcvh-xf52-2cwm (high) — ffuf denial of service (OOM) via HTTP response decompression bomb

[GHSA] GHSA-jcvh-xf52-2cwm (high) — ffuf denial of service (OOM) via HTTP response decompression bomb

highgithub_advisoriesPublished 2026-09-03

GHSA-jcvh-xf52-2cwm Severity: high CVE: CVE-2026-73232

ffuf denial of service (OOM) via HTTP response decompression bomb

### Summary

A malicious or attacker-controlled target server can crash ffuf with an out-of-memory condition by returning a compressed HTTP response that decompresses to a very large body (a decompression bomb). This works against default usage with no special flags.

##

Indicators of compromise

Original source: https://github.com/advisories/GHSA-jcvh-xf52-2cwm