CVE-2026-61541: Zapros has an Unbounded Content-Encoding decompression chain that allows denial of service
Who is impacted:
- Any application using Zapros to make HTTP requests to untrusted servers
- Applications that follow redirects to attacker-controlled hosts
Attack vector:
- A malicious HTTP server returns a response with many chained content encodings. When the client attempts to decode, it creates a deeply nested decompression chain consuming excessive resources.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-61541 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →