THREAT OPS › Threat News › [GHSA] GHSA-jcvh-xf52-2cwm (high) — ffuf denial of service (OOM) via HTTP response decompression bomb
[GHSA] GHSA-jcvh-xf52-2cwm (high) — ffuf denial of service (OOM) via HTTP response decompression bomb
GHSA-jcvh-xf52-2cwm Severity: high CVE: CVE-2026-73232
ffuf denial of service (OOM) via HTTP response decompression bomb
### Summary
A malicious or attacker-controlled target server can crash ffuf with an out-of-memory condition by returning a compressed HTTP response that decompresses to a very large body (a decompression bomb). This works against default usage with no special flags.
##
Indicators of compromise
- CVE-2026-73232cve
- http://target/FUZZurl
Original source: https://github.com/advisories/GHSA-jcvh-xf52-2cwm