A AegiFlow
HIGHCVSS 7.5EPSS 0.4%

CVE-2026-73232

CVE-2026-73232 updated by NVD

Published
2026-09-03
Modified
2026-09-20
EPSS percentile
37%
Sources
github-advisory, nvd

Summary

ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory denial of service because the response size guard in pkg/runner/simple.go checks only the compressed Content-Length while io.ReadAll reads gzip, brotli, deflate, transparently decompressed, or chunked response bodies without a decompressed-size bound. This issue is fixed in version 2.2.0.

Affected packages

EcosystemPackageAffected versionsFixed versions
Gogithub.com/ffuf/ffuf
Gogithub.com/ffuf/ffuf/v22.2.0

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.