CVE-2026-40036EPSS p54.8%
CVE-2026-40036CVE-2026-40036
ryandfir / unfurl
Description
Unfurl before 2026.04 contains an unbounded zlib decompression vulnerability in parse_compressed.py that allows remote attackers to cause denial of service. Attackers can submit highly compressed payloads via URL parameters to the /json/visjs endpoint that expand to gigabytes, exhausting server memory and crashing the service.
Scoring
| CVSS | 7.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| EPSS | 0.79% probability of exploitation · percentile 54.8% · 2026-10-06T12:00:23Z |
| Last modified | 2026-07-24 |