highCVSS 7.5Vulnerability

GHSA-c3f2-qg8v-25q2

### Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-h5qv-qjv4-pc5m. This link is maintained to preserve external references. ### Original Description Unfurl before 2026.04 contains an unbounded zlib decompression vulnerability in parse_compressed.py that allows remote attackers to cause denial of service. Attackers can submit highly compressed payloads via URL parameters to the /json/visjs endpoint that expand to gigabytes, exhausting server memory and crashing the service.

Properties

ghsa_id
GHSA-c3f2-qg8v-25q2
summary
Duplicate Advisory: Unfurl's unbounded zlib decompression allows decompression bomb DoS
severity
high
cvss_score
7.5
cve_id
GHSA-c3f2-qg8v-25q2
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
is_ghsa_only
true
ghsa_published
2026-04-09T00:31:59Z
source_url
https://github.com/advisories/GHSA-c3f2-qg8v-25q2
ghsa_updated
2026-04-10T17:18:33Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]pip/dfir-unfurl

REPORTED_BY (1)

[Source]GitHub Advisory Database

AFFECTS (1)

[Software]pip/dfir-unfurl

HAS_WEAKNESS (1)

[Weakness]Improper Handling of Highly Compressed Data (Data Amplification)

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-c3f2-qg8v-25q2 (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal