Bug 2353383 (CVE-2025-30153) - CVE-2025-30153 github.com/getkin/kin-openapi/openapi3filter: Improper Handling of Highly Compressed Data (Data Amplification) in github.com/getkin/kin-openapi/openapi3filter
Summary: CVE-2025-30153 github.com/getkin/kin-openapi/openapi3filter: Improper Handlin...
Keywords:
Status: NEW
Alias: CVE-2025-30153
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2353401 2353402 2353403 2353404 2353405 2353406
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-03-19 17:01 UTC by OSIDB Bzimport
Modified: 2025-03-25 22:18 UTC (History)
6 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-03-19 17:01:06 UTC
kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131.0, when validating a request with a multipart/form-data schema, if the OpenAPI schema allows it, an attacker can upload a crafted ZIP file (e.g., a ZIP bomb), causing the server to consume all available system memory. The root cause comes from the ZipFileBodyDecoder, which is registered automatically by the module (contrary to what the documentation says). This vulnerability is fixed in 0.131.0.


Note You need to log in before you can comment on or make changes to this bug.