Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-53433

Опубликовано: 30 июн. 2026
Источник: redhat
CVSS3: 7.5

Описание

fzf is vulnerable to a Denial of Service (DoS) due to inefficient HTTP body processing in the --listen mode due to inefficient HTTP body processing using repeated string concatenation, resulting in quadratic time complexity (O(n²)). A crafted POST request with many small segments can trigger excessive CPU usage during request handling.This allows a single malicious request to monopolize the single‑threaded HTTP server, blocking all other clients and resulting in denial of service. This issue was fixed in version 0.73.1.

A flaw was found in fzf, a command-line fuzzy finder. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by sending a crafted POST request with many small segments to the --listen mode. The inefficient HTTP body processing, which uses repeated string concatenation, leads to quadratic time complexity, causing excessive CPU usage and blocking other clients.

Отчет

A flaw was found in fzf, a command-line fuzzy finder. When fzf is running in --listen mode (a non-default, opt-in feature), inefficient HTTP body processing using repeated string concatenation results in quadratic time complexity. A crafted POST request can monopolize the single-threaded HTTP server, causing denial of service. Red Hat has corrected the impact from IMPORTANT to MODERATE — the original AI-Bot CVSS of 7.5 (AV:N/AC:L) did not account for the --listen mode being a non-default feature that must be explicitly enabled. The CVEORG CVSSv4 score of 5.7 (AV:L/AT:P) more accurately reflects the prerequisite nature of the attack.

Меры по смягчению последствий

Do not use fzf's --listen mode in untrusted network environments. If --listen is required, restrict network access to the fzf listener port using firewall rules.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1046
https://bugzilla.redhat.com/show_bug.cgi?id=2494891fzf: fzf: Denial of Service via inefficient HTTP body processing

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

fzf is vulnerable to a Denial of Service (DoS) due to inefficient HTTP body processing in the --listen mode due to inefficient HTTP body processing using repeated string concatenation, resulting in quadratic time complexity (O(n²)). A crafted POST request with many small segments can trigger excessive CPU usage during request handling.This allows a single malicious request to monopolize the single‑threaded HTTP server, blocking all other clients and resulting in denial of service. This issue was fixed in version 0.73.1.

CVSS3: 7.5
nvd
около 1 месяца назад

fzf is vulnerable to a Denial of Service (DoS) due to inefficient HTTP body processing in the --listen mode due to inefficient HTTP body processing using repeated string concatenation, resulting in quadratic time complexity (O(n²)). A crafted POST request with many small segments can trigger excessive CPU usage during request handling.This allows a single malicious request to monopolize the single‑threaded HTTP server, blocking all other clients and resulting in denial of service. This issue was fixed in version 0.73.1.

CVSS3: 7.5
debian
около 1 месяца назад

fzf is vulnerable to a Denial of Service (DoS) due to inefficient HTTP ...

CVSS3: 7.5
github
около 1 месяца назад

fzf is vulnerable to a Denial of Service (DoS) due to inefficient HTTP body processing in the --listen mode due to inefficient HTTP body processing using repeated string concatenation, resulting in quadratic time complexity (O(n²)). A crafted POST request with many small segments can trigger excessive CPU usage during request handling.This allows a single malicious request to monopolize the single‑threaded HTTP server, blocking all other clients and resulting in denial of service. This issue was fixed in version 0.73.1.

7.5 High

CVSS3