CVE-2023-3635
HIGH 7.5EPSS 1.3%
GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. This may lead to denial of service of the Okio client when handling a crafted GZIP archive, by using the GzipSource class.
- CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - CVSS v3.1
- 5.9 MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H - CVSS v3.1
- 5.9 MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H - EPSS
- 1.25% chance of exploitation in the next 30 days, 67th percentile
- Published
- 2023-07-12
- Updated
- 2024-10-23
Proof-of-concept exploits (1)
- JoshuaASmith/reproducer-okio-cve-2023-36350★ · 2026-08-25