Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:32905
HistoryNov 11, 2021 - 5:24 a.m.

Denial Of Service (DoS)

2021-11-1105:24:47
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5
denial of service
gzip bomb
cloudflare

EPSS

0.001

Percentile

44.1%

github.com/cloudflare/cfrpki is vulnerable to denial of service. The vulnerability exists due to the lack of check of the size of the incoming compressed file allowing an attacker to crash the system via a GZIP bomb attack.