OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-61652

HIGH · CVSS 8.7 EPSS 0.44% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Zapros, a Python HTTP client, is vulnerable to denial of service due to memory exhaustion in versions prior to 0.14.0, particularly when handling streamed compressed responses. This vulnerability allows attackers to exploit the chunk size handling, potentially leading to significant memory overflow. Developers and organizations using Zapros for HTTP requests should prioritize upgrading to version 0.14.0 or implementing the recommended workarounds to mitigate the risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-61652
Severity
HIGH
CVSS
8.7
EPSS
0.44%

Original NVD Description

Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service via memory exhaustion. The issue affects all callers who streamed compressed responses relying on the chunk size — explicit (`iter_bytes(chunk_size=...)`) or the default — to bound memory. The decoder ignored that bound, so a chunk could be far larger than requested and a single compressed response could overflow memory. Version 0.14.0 contains a patch. Some workarounds are available. Read the still-compressed body with `Response.iter_raw()` / `Response.async_iter_raw()`, which bypass the built-in decoders, and decompress it yourself with an explicit output-size bound (e.g. `zlib`'s `max_length`), aborting once a configured limit is exceeded. Where feasible, send `Accept-Encoding: identity` to disable response compression so bodies are not decompressed client-side. Avoid decoding response bodies from untrusted servers.