ffuf vulnerability

ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory denial of service because the response size guard in pkg/runner/simple.go checks only the compressed Content-Length while io.ReadAll reads gzip, brotli, deflate, transparently decompressed, or chunked response bodies without a decompressed-size bound. This issue is fixed in version 2.2.0.

Published 11 Aug 2026Updated 18 Sep 20264 sources
CVSS 7.5

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.