CVE-2026-53659
http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.49.0.0, ServerFilters.GZip, RequestFilters.GunZip, and the underlying Gzip request-body decompression functions impose no limit on decompressed size. An unauthenticated client can send a small gzip-encoded request body that expands to gigabytes, exhausting the JVM heap and denying service to other clients. The fix uses SizeLimitedInputStream to enforce a default 10 MiB limit, causes ServerFilters.GZip and RequestFilters.GunZip to return 413 Request Entity Too Large, and causes other decompression paths to throw SizeLimitExceededException. This issue is fixed in versions 4.51.0.0, 5.42.0.0, and 6.49.0.0.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.44%
- CWE
- CWE-409
- Published
- 2026-09-14
- Last modified
- 2026-09-14
Affected products
- http4k http4k
- http4k http4k
- http4k http4k
Weakness type
Related vulnerabilities
- CVE-2025-66471 — urllib3 Streaming API improperly handles highly compressed data
- CVE-2026-22776 — cpp-httplib vulnerable to a denial of service (DOS) using a zip bomb
- CVE-2026-5132 — Unbounded zlib decompression in Calls SDP WebSocket messages
- CVE-2026-15814 — Uploading a crafted image causes excessive memory allocation in the Mattermost Server
- CVE-2026-14298 — Boards archive import endpoint allows resource exhaustion via zip bomb and file size limit bypass in Mattermost
- CVE-2026-10819 — Mattermost Server Denial of Service via Animated GIF Emoji Upload
- CVE-2026-21441 — urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API)
- CVE-2024-7765 — Denial of Service in h2oai/h2o-3