brotli is vulnerable to Denial of Service (DoS)
32
Low Risk
The BroCatli concatenator in src/concat/mod.rs only recognizes a Brotli sub-stream's header as complete once exactly 4 or 5 bytes have been buffered. A short, complete empty sub-stream that terminates before that point never satisfies the check, so BroCatli::stream keeps reporting NeedsMoreInput and stalls indefinitely even though the concatenated input has already ended. This lets malformed or truncated concatenated Brotli input hang stream processing instead of completing or returning an error. The fix also recognizes the window, ISLAST, and ISLASTEMPTY bits as soon as they are buffered, so short empty streams are detected without waiting for bytes that never arrive.
You are affected if you are using a version that falls within the vulnerable range and you use BroCatli to concatenate Brotli streams that may include short or malformed sub-streams.
brotli is vulnerable to Denial of Service (DoS) in versions 1.0.7 - 8.0.4.
Upgrade the brotli library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.