PT-2026-31471 · Unfurl · Unfurl
Mobasi-Team
·
Published
2026-01-29
·
Updated
2026-04-09
·
CVE-2026-40036
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Unfurl versions prior to 2026.04
Description
Unfurl contains a flaw in the
parse compressed.py component due to unbounded zlib decompression. Remote attackers can leverage this to cause a denial of service. Specifically, attackers can send large, compressed payloads through URL parameters to the /json/visjs API endpoint. These payloads expand to gigabytes, consuming server memory and leading to service crashes.Recommendations
Update to version 2026.04 or later.
Fix
Allocation of Resources Without Limits
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Unfurl