Περιγραφή
fzf is vulnerable to a Denial of Service (DoS) due to inefficient HTTP body processing in the --listen mode due to inefficient HTTP body processing using repeated string concatenation, resulting in quadratic time complexity (O(n²)). A crafted POST request with many small segments can trigger excessive CPU usage during request handling.This allows a single malicious request to monopolize the single‑threaded HTTP server, blocking all other clients and resulting in denial of service. This issue was fixed in version 0.73.1.
CVSS 7.5EPSS 0.212%Κίνδυνος 0.76
Προβολή πηγής- Δημοσίευση
- 2026-06-30 13:19:13
- Επηρεαζόμενες εκδόσεις
- <0.73.1
- Τύπος
- Άλλο
- Διάνυσμα
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H