VDB
RHSA-2026%3A2974
RHSA-2026%3A2974
PUBLISHED
CVSS 7.5 HIGH
Scrapy are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompression implementation. The protection mechanism against decompression bombs fails to mitigate the brotli variant, allowing remote servers to crash clients with less than 80GB of available memory. This occurs because brotli can achieve extremely high compression ratios for zero-filled data, leading to excessive memory consumption during decompression.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rhcos-s390x-414.92.202602171627-0 as a component of Red Hat OpenShift Container Platform 4.14 | rhcos-s390x-414.92.202602171627-0, rhcos-s390x-414.92.202602171627-0, rhcos-s390x-414.92.202602171627-0 |
| Red Hat | rhcos-aarch64-414.92.202602171627-0 as a component of Red Hat OpenShift Container Platform 4.14 | rhcos-aarch64-414.92.202602171627-0, rhcos-aarch64-414.92.202602171627-0, * |
| Red Hat | rhcos-s390x-414.92.202602171627-0 as a component of Red Hat OpenShift Container Platform 4.14 | rhcos-s390x-414.92.202602171627-0, 414.92.202602171627-0 |
| Red Hat | rhcos-ppc64le-414.92.202602171627-0 as a component of Red Hat OpenShift Container Platform 4.14 | rhcos-ppc64le-414.92.202602171627-0, 414.92.202602171627-0 |
| Red Hat | rhcos-x86_64-414.92.202602171627-0 as a component of Red Hat OpenShift Container Platform 4.14 | rhcos-x86_64-414.92.202602171627-0, 414.92.202602171627-0 |
| Red Hat | rhcos-x86_64-414.92.202602171627-0 as a component of Red Hat OpenShift Container Platform 4.14 | rhcos-x86_64-414.92.202602171627-0, rhcos-x86_64-414.92.202602171627-0, rhcos-x86_64-414.92.202602171627-0 |
| Red Hat | rhcos-aarch64-414.92.202602171627-0 as a component of Red Hat OpenShift Container Platform 4.14 | rhcos-aarch64-414.92.202602171627-0, 414.92.202602171627-0 |
| Red Hat | rhcos-ppc64le-414.92.202602171627-0 as a component of Red Hat OpenShift Container Platform 4.14 | rhcos-ppc64le-414.92.202602171627-0, *, rhcos-ppc64le-414.92.202602171627-0 |
Timeline
- Feb 26, 2026 CVE Published
- Apr 24, 2026 Security Advisory
- Apr 24, 2026 Security Advisory
- Apr 29, 2026 Distribution Patch
- Jul 27, 2026 CVE Updated
- Jul 27, 2026 Distribution Patch
- Jul 27, 2026 Security Advisory
- Jul 27, 2026 Security Advisory
- Jul 27, 2026 Security Advisory
- Jul 27, 2026 Security Advisory
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2408762 issue
- https://www.cve.org/CVERecord?id=CVE-2025-15467 advisory
- https://access.redhat.com/security/cve/CVE-2025-66293 advisory
- https://www.cve.org/CVERecord?id=CVE-2025-66293 advisory
- https://github.com/pnggroup/libpng/commit/a05a48b756de63e3234ea6b3b938b8f5f862484a advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-6176 advisory
- https://access.redhat.com/security/cve/CVE-2025-9230 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-66293 advisory
- https://github.com/pnggroup/libpng/issues/764 advisory
- https://access.redhat.com/security/cve/CVE-2025-6176 advisory
- https://huntr.com/bounties/2c26a886-5984-47ee-a421-0d5fe1344eb0 advisory
- https://gitlab.gnome.org/GNOME/glib/-/issues/3827 advisory
- https://access.redhat.com/errata/RHSA-2026:2974 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2396054 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2430376 issue
- https://nvd.nist.gov/vuln/detail/CVE-2025-9230 advisory
- https://access.redhat.com/security/cve/CVE-2025-13601 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-13601 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-15467 advisory
…and 10 more