CVE-2023-28119High· 7.5▾ Twilightcrewjam/saml vulnerable to Denial Of Service Via Deflate Decompression Bomb
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.0%
Our use of flate.NewReader does not limit the size of the input. The user could pass more than 1 MB of data in the HTTP request to the processing functions, which will be decompressed server-side using the Deflate algorithm. Therefore, after repeating the same request multiple times, it is possible to achieve a reliable crash since the operating system kills the process.
github.com/crewjam/saml < 0.4.13Upgrade to a patched release:
github.com/crewjam/saml 0.4.13Connected by shared product, vendor, weakness, or advisory.