Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39331
HistoryFeb 18, 2023 - 5:23 a.m.

Denial Of Service (DoS)

2023-02-1805:23:01
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
23
curl
vulnerability
dos
attack
headers
compression
crash

0.001 Low

EPSS

Percentile

43.9%

curl is vulnerable to Denial of Service (DoS). The vulnerability occurs because curl caps chained HTTP compression algorithms on per header basis. This allows an attacker to insert a virtually unlimited number of compression steps simply by using many headers leading to a crash.