Related Vulnerabilities: CVE-2022-32206  

A vulnerability was found in curl. This issue occurs because the number of acceptable "links" in the "decompression chain" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps. This flaw leads to a denial of service, either by mistake or by a malicious actor.

Description

A vulnerability was found in curl. This issue occurs because the number of acceptable "links" in the "decompression chain" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps. This flaw leads to a denial of service, either by mistake or by a malicious actor.

Additional Information

  • Bugzilla 2099300: CVE-2022-32206 curl: HTTP compression denial of service
  • CWE-770: Allocation of Resources Without Limits or Throttling
  • FAQ: Frequently asked questions about CVE-2022-32206