Known Vulnerabilities for Gzip by Gnu
Listed below are 10 of the newest known vulnerabilities associated with "Gzip" by "Gnu".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-59939 json | httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTT... | Not Provided | 2026-07-08 | 2026-07-10 |
| CVE-2026-59873 json | node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on t... | Not Provided | 2026-07-08 | 2026-07-08 |
| CVE-2026-59803 json | rpcx through 1.9.3, fixed in commit 047aec1, contains a denial-of-service vulnerability in protocol.Message.Decode (protocol/... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-56138 json | AIL framework contains a path traversal vulnerability in the /objects/item/diff endpoint. The endpoint accepts item identifie... | Not Provided | 2026-06-19 | 2026-06-22 |
| CVE-2026-53430 json | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-grpc grpc (GRPC.Compressor.Gzip, GRP... | Not Provided | 2026-06-15 | 2026-06-16 |
| CVE-2026-49855 json | Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines pr... | Not Provided | 2026-07-14 | 2026-07-16 |
| CVE-2026-49755 json | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in wojtekmach Req allows attacker-controlled H... | Not Provided | 2026-06-08 | 2026-06-08 |
| CVE-2026-48594 json | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-tesla tesla allows a denial of servi... | Not Provided | 2026-06-02 | 2026-06-04 |
| CVE-2026-48043 json | Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versi... | Not Provided | 2026-06-12 | 2026-07-21 |
| CVE-2026-46483 json | Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimuntar(... | Not Provided | 2026-05-15 | 2026-05-15 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gnu | Gzip | 1.9 | |||
| Application | Gnu | Gzip | 1.8 | |||
| Application | Gnu | Gzip | 1.7 | |||
| Application | Gnu | Gzip | 1.6 | |||
| Application | Gnu | Gzip | 1.5 | |||
| Application | Gnu | Gzip | 1.4 | |||
| Application | Gnu | Gzip | 1.3.9 | |||
| Application | Gnu | Gzip | 1.3.8 | |||
| Application | Gnu | Gzip | 1.3.7 | |||
| Application | Gnu | Gzip | 1.3.6 | |||
| Application | Gnu | Gzip | 1.3.5 | |||
| Application | Gnu | Gzip | 1.3.4 | |||
| Application | Gnu | Gzip | 1.3.3 | |||
| Application | Gnu | Gzip | 1.3.14 | |||
| Application | Gnu | Gzip | 1.3.13 | |||
| Application | Gnu | Gzip | 1.3.12 | |||
| Application | Gnu | Gzip | 1.3.11 | |||
| Application | Gnu | Gzip | 1.3.10 | |||
| Application | Gnu | Gzip | 1.3 | |||
| Application | Gnu | Gzip | 1.2.4a |