Impact
Pomerium’s pre‑authentication URL decryption routine performs zstd decompression of attacker‑controlled data without an output‑memory limit. The result is a use‑of‑memory vulnerability that can allocate hundreds of megabytes per request, exhausting the proxy’s RAM and causing crashes or degraded performance. The flaw is limited to stateless deployments; stateful callbacks verify an HMAC signature before decryption and are not affected. The combination of high memory usage and lack of authentication enables a remote denial of service but not code execution.
Affected Systems
All versions of the Pomerium access proxy older than 0.32.8 are vulnerable. The fix is included in release v0.32.8 and later. Upgrades to a supported version are required to mitigate the issue.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity vulnerability. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the issue is not currently listed in the CISA KEV catalog. An attacker can trigger the flaw by making an unauthenticated HTTP request to the /.pomerium/callback endpoint with a specially crafted HPKE payload, so the attack vector is web‑based and requires network reachability to the proxy. While no public exploits are reported, the combination of high impact and low EPSS warrants immediate attention for deployments that expose the callback endpoint to untrusted clients.
OpenCVE Enrichment
Github GHSA