Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-273h-gvwr-c3qj | CrowdSec LAPI: Denial of Service via Unbounded Gzip Decompression |
Thu, 23 Jul 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Crowdsecurity
Crowdsecurity crowdsec |
|
| Vendors & Products |
Crowdsecurity
Crowdsecurity crowdsec |
Fri, 17 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 16 Jul 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CrowdSec offers crowdsourced protection against malicious IPs. From 1.7.0 until 1.7.8, the LAPI router used gin-contrib/gzip with DefaultDecompressHandle globally in pkg/apiserver/controllers/controller.go, causing /v1/watchers and /v1/watchers/login to decompress unauthenticated gzip-compressed JSON request bodies without enforcing a maximum decompressed size and allowing excessive heap allocation that can make LAPI unreachable. This issue is fixed in version 1.7.8. | |
| Title | CrowdSec LAPI: Denial of Service via Unbounded Gzip Decompression | |
| Weaknesses | CWE-409 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-17T13:50:30.497Z
Reserved: 2026-05-08T16:23:33.264Z
Link: CVE-2026-44981
Updated: 2026-07-17T13:50:22.816Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-25T05:15:03Z
Github GHSA