{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3azaproszapros/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:zapros:zapros:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-61652"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["zapros (\u003c 0.14.0)"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe zapros library is susceptible to a denial-of-service vulnerability (CVE-2026-61652) caused by improper memory management during the decompression of HTTP response bodies. In affected versions prior to 0.14.0, streaming decoders for gzip, deflate, brotli, and zstd encodings ignore the requested chunk size provided by the caller.\u003c/p\u003e\n\u003cp\u003eAn attacker controlling a malicious server can transmit a specially crafted, highly compressed payload (a decompression bomb) that expands to a significantly larger size upon decoding. Because the library fails to limit the output of each decompression step to the requested chunk size, a single chunk can force the client application to allocate excessive memory, leading to process instability or termination. This is particularly critical for applications that process data from untrusted sources, as the memory exhaustion is triggered automatically upon reading the response stream.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability results in a denial-of-service condition due to heap memory exhaustion. Applications using zapros to fetch data from untrusted or compromised endpoints are at risk of crashing when handling malicious compressed payloads. The impact is significant for services that rely on zapros for high-frequency or long-running data ingestion, as a single malicious response can terminate the service process.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for development and security operations:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the zapros library dependency to version 0.14.0 or later to ensure that decompression output is bounded to the requested chunk size.\u003c/li\u003e\n\u003cli\u003eFor applications that cannot be immediately patched, transition to reading responses using Response.iter_raw() and implement a manual, bounded decompression logic that aborts when a defined size limit is exceeded.\u003c/li\u003e\n\u003cli\u003eDisable response compression in client requests where possible by sending 'Accept-Encoding: identity' to prevent the library's decoders from processing potentially malicious payloads.\u003c/li\u003e\n\u003cli\u003eAvoid automated decoding of response bodies received from untrusted or third-party servers.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T01:58:10Z","date_published":"2026-09-24T01:58:10Z","id":"https://feed.craftedsignal.io/briefs/2026-09-zapros-memory-exhaustion/","summary":"The zapros library fails to enforce memory bounds during response decompression, allowing remote servers to trigger denial-of-service via memory exhaustion (CVE-2026-61652).","title":"Zapros Decompression Bomb Vulnerability in Streaming Decoders","url":"https://feed.craftedsignal.io/briefs/2026-09-zapros-memory-exhaustion/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:zapros:zapros:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}