Duplicate Advisory: Unfurl's unbounded zlib decompression allows decompression bomb DoS
High severity
GitHub Reviewed
Published
Apr 9, 2026
to the GitHub Advisory Database
•
Updated Apr 10, 2026
Withdrawn
This advisory was withdrawn on Apr 10, 2026
Description
Published by the National Vulnerability Database
Apr 8, 2026
Published to the GitHub Advisory Database
Apr 9, 2026
Reviewed
Apr 10, 2026
Withdrawn
Apr 10, 2026
Last updated
Apr 10, 2026
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-h5qv-qjv4-pc5m. This link is maintained to preserve external references.
Original Description
Unfurl before 2026.04 contains an unbounded zlib decompression vulnerability in parse_compressed.py that allows remote attackers to cause denial of service. Attackers can submit highly compressed payloads via URL parameters to the /json/visjs endpoint that expand to gigabytes, exhausting server memory and crashing the service.
References