CVE-2026-40036 is an unbounded zlib decompression vulnerability affecting Unfurl versions before 2026.04 in the parse_compressed.py module. The flaw allows remote attackers to submit highly compressed payloads through the /json/visjs endpoint that expand to gigabytes when decompressed, causing denial of service by exhausting server memory and crashing the service. The vulnerability carries a CVSS 3.1 score of 7.5 (HIGH) with a network-based attack vector that requires no authentication or user interaction, making it relatively easy to exploit. The attack has high availability impact as it directly results in service disruption, though confidentiality and integrity are not affected. There is currently no evidence of active exploitation in the wild, as the vulnerability is not listed on the Known Exploited Vulnerabilities catalog and remains inactive on threat tracking lists. The EPSS score of 0.00143 indicates this vulnerability has lower probability of exploitation compared to most CVEs, suggesting limited community attention and low immediate threat despite its technical severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2026.04CPE matchmatch criteria | cpe:2.3:a:ryandfir:unfurl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.