216.73.216.226

CVE-2025-30153

· Published 19/03/2025 16:15 · Modified 19/03/2025 16:15

Labels: CVE-2025-30153 2025-03-19CVE-2025-30153CWE-409[email protected]

Essential information

Published
19/03/2025 16:15
Modified
19/03/2025 16:15
Author
Creator
CVSS
7.5 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS metrics

Description

kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131.0, when validating a request with a multipart/form-data schema, if the OpenAPI schema allows it, an attacker can upload a crafted ZIP file (e.g., a ZIP bomb), causing the server to consume all available system memory. The root cause comes from the ZipFileBodyDecoder, which is registered automatically by the module (contrary to what the documentation says). This vulnerability is fixed in 0.131.0.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
kin / openapi cpe:2.3:a:kin:openapi:*:*:*:*:*:*:*:*
kin / openapi cpe:2.3:a:kin:openapi:0.131.0:*:*:*:*:*:*:*

References