Description
http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.49.0.0, ServerFilters.GZip, RequestFilters.GunZip, and the underlying Gzip request-body decompression functions impose no limit on decompressed size. An unauthenticated client can send a small gzip-encoded request body that expands to gigabytes, exhausting the JVM heap and denying service to other clients. The fix uses SizeLimitedInputStream to enforce a default 10 MiB limit, causes ServerFilters.GZip and RequestFilters.GunZip to return 413 Request Entity Too Large, and causes other decompression paths to throw SizeLimitExceededException. This issue is fixed in versions 4.51.0.0, 5.42.0.0, and 6.49.0.0.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (memory exhaustion)
Action: Upgrade
AI Analysis

Impact

Prior to release 4.51.0.0, 5.42.0.0, and 6.49.0.0, the http4k ServerFilters.GZip, RequestFilters.GunZip and underlying Gzip decompression paths set no limit on the size of the uncompressed data. An unauthenticated client could send a small gzip-encoded request body that expands to gigabytes, exhausting the JVM heap and denying service to other clients. The vulnerability has been patched by incorporating SizeLimitedInputStream, which imposes a default 10 MiB limit and causes the filters to return a 413 Request Entity Too Large response or throw SizeLimitExceededException when exceeded.

Affected Systems

The vulnerability affects any http4k installation using ServerFilters.GZip, RequestFilters.GunZip, or any of the underlying gzip decompression paths that predates the release of 4.51.0.0, 5.42.0.0, or 6.49.0.0. System administrators should verify the http4k version in use and list any applications built with these filters as vulnerable.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, and while an EPSS score is <1%, the possibility of exploit is real because an unauthenticated client can trigger the attack simply by sending a gzip request. No CISA KEV listing means it has not been confirmed as a known exploited vulnerability, but the lack of a limit creates an obvious attack surface. An attacker can use an unrestricted network connection to the http4k service to misuse the decompression logic and exhaust memory, leading to service degradation or crash.

Generated by OpenCVE AI on September 20, 2026 at 23:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade http4k to version 4.51.0.0 or newer (or 5.42.0.0 / 6.49.0.0) to enable SizeLimitedInputStream and enforce the default 10 MiB limit, which returns 413 Request Entity Too Large for oversized bodies.
  • If upgrading modify existing filters to wrap the input stream with a size‑limiting stream before decompression or reject request bodies that could exceed a safe threshold.
  • Configure JVM monitoring and alerting for abnormal heap growth or OutOfMemoryErrors that could indicate exploitation attempts, and configure load balancers or reverse proxies to enforce request size limits where possible.

Generated by OpenCVE AI on September 20, 2026 at 23:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-g4w2-6h2r-3m3w http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoS
History

Sun, 27 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Http4k
Http4k http4k
Vendors & Products Http4k
Http4k http4k

Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.49.0.0, ServerFilters.GZip, RequestFilters.GunZip, and the underlying Gzip request-body decompression functions impose no limit on decompressed size. An unauthenticated client can send a small gzip-encoded request body that expands to gigabytes, exhausting the JVM heap and denying service to other clients. The fix uses SizeLimitedInputStream to enforce a default 10 MiB limit, causes ServerFilters.GZip and RequestFilters.GunZip to return 413 Request Entity Too Large, and causes other decompression paths to throw SizeLimitExceededException. This issue is fixed in versions 4.51.0.0, 5.42.0.0, and 6.49.0.0.
Title http4k: Unbounded gzip decompression in `ServerFilters.GZip` / `RequestFilters.GunZip` allowed memory-exhaustion DoS
Weaknesses CWE-409
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T19:03:54.830Z

Reserved: 2026-06-09T20:50:36.877Z

Link: CVE-2026-53659

cve-icon Vulnrichment

Updated: 2026-09-14T19:03:51.833Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:17:51.610

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-53659

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-14T17:29:57Z

Links: CVE-2026-53659 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T06:00:12Z

Weaknesses
  • CWE-409

    Improper Handling of Highly Compressed Data (Data Amplification)