CVE-2026-66913

Lookyloo did not enforce limits on the decompressed size of uploaded capture archives and compressed HAR files. An attacker could submit a specially crafted ZIP, gzip, or zlib-compressed capture containing data that expands to a very large size during processing. Because the application decompressed this content directly in memory without first limiting the output size, processing the malicious capture could exhaust available memory, terminate a web or worker process, or make the Lookyloo instance unavailable. The vulnerability affects both full Lookyloo capture archive imports and API submissions containing gzip-compressed HAR data. Repeated exploitation could cause a persistent denial-of-service condition until the affected processes or instance are restarted. The patch introduces: * A 1 GB cumulative uncompressed-size limit for imported capture archives. * Size-limited gzip and zlib decompression for compressed HAR files. * Explicit detection and handling of suspected zip bombs. * An HTTP 400 response when an oversized compressed HAR file is submitted through the API.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-07-28 13:19

Updated : 2026-07-30 16:55


NVD link : CVE-2026-66913

Mitre link : CVE-2026-66913

CVE.ORG link : CVE-2026-66913


JSON object : View

Products Affected

No product.

CWE
CWE-400

Uncontrolled Resource Consumption