Количество 6
Количество 6
CVE-2025-30153
kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131.0, when validating a request with a multipart/form-data schema, if the OpenAPI schema allows it, an attacker can upload a crafted ZIP file (e.g., a ZIP bomb), causing the server to consume all available system memory. The root cause comes from the ZipFileBodyDecoder, which is registered automatically by the module (contrary to what the documentation says). This vulnerability is fixed in 0.131.0.
CVE-2025-30153
kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131.0, when validating a request with a multipart/form-data schema, if the OpenAPI schema allows it, an attacker can upload a crafted ZIP file (e.g., a ZIP bomb), causing the server to consume all available system memory. The root cause comes from the ZipFileBodyDecoder, which is registered automatically by the module (contrary to what the documentation says). This vulnerability is fixed in 0.131.0.
CVE-2025-30153
kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131 ...
GHSA-wq9g-9vfc-cfq9
Improper Handling of Highly Compressed Data (Data Amplification) in github.com/getkin/kin-openapi/openapi3filter
openSUSE-SU-2026:20788-1
Security update for mcphost
openSUSE-SU-2026:20940-1
Security update for grafana
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-30153 kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131.0, when validating a request with a multipart/form-data schema, if the OpenAPI schema allows it, an attacker can upload a crafted ZIP file (e.g., a ZIP bomb), causing the server to consume all available system memory. The root cause comes from the ZipFileBodyDecoder, which is registered automatically by the module (contrary to what the documentation says). This vulnerability is fixed in 0.131.0. | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
CVE-2025-30153 kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131.0, when validating a request with a multipart/form-data schema, if the OpenAPI schema allows it, an attacker can upload a crafted ZIP file (e.g., a ZIP bomb), causing the server to consume all available system memory. The root cause comes from the ZipFileBodyDecoder, which is registered automatically by the module (contrary to what the documentation says). This vulnerability is fixed in 0.131.0. | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
CVE-2025-30153 kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131 ... | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
GHSA-wq9g-9vfc-cfq9 Improper Handling of Highly Compressed Data (Data Amplification) in github.com/getkin/kin-openapi/openapi3filter | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
openSUSE-SU-2026:20788-1 Security update for mcphost | 3 месяца назад | |||
openSUSE-SU-2026:20940-1 Security update for grafana | 3 месяца назад |
Уязвимостей на страницу