CPE
The zapros library fails to enforce memory bounds during response decompression, allowing remote servers to trigger denial-of-service via memory exhaustion (CVE-2026-61652).