CVE-2026-61541

Summary

Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service when an application requests content from an untrusted server, or follows a redirect to one, because a malicious response containing an excessive number of chained Content-Encoding values causes Zapros to construct a deeply nested decompression chain that consumes excessive resources. Version 0.14.0 patches the vulnerability by limiting responses to five content-encoding layers and raising DecodingError when that limit is exceeded. As a workaround, applications can add response middleware that inspects the Content-Encoding header and rejects responses containing more than a safe number of encoding layers.

Affected Software

VendorProductVersion RangeStatus
kap-shzapros< 0.14.0affected

Weaknesses

  • CWE-770: CWE-770: Allocation of Resources Without Limits or Throttling

References