Intel

AIKIDO-2026-319534

brotli is vulnerable to Denial of Service (DoS)

Denial of Service (DoS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published 5 days ago

32

Low Risk

This Affects:

RUSTbrotli
1.0.7 - 8.0.4
Fixed in 9.0.0
Are you affected? Scan for Free

TL;DR

The BroCatli concatenator in src/concat/mod.rs only recognizes a Brotli sub-stream's header as complete once exactly 4 or 5 bytes have been buffered. A short, complete empty sub-stream that terminates before that point never satisfies the check, so BroCatli::stream keeps reporting NeedsMoreInput and stalls indefinitely even though the concatenated input has already ended. This lets malformed or truncated concatenated Brotli input hang stream processing instead of completing or returning an error. The fix also recognizes the window, ISLAST, and ISLASTEMPTY bits as soon as they are buffered, so short empty streams are detected without waiting for bytes that never arrive.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you use BroCatli to concatenate Brotli streams that may include short or malformed sub-streams.

Background info

brotli is vulnerable to Denial of Service (DoS) in versions 1.0.7 - 8.0.4.

How to fix this

Upgrade the brotli library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform