Showing 1 vulnerability on this page for IO::Compress::Brotli

Signals CISA KEV Ransomware Nuclei
TIMLEGGE vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

IO::Compress::Brotli versions prior to 0.007 for Perl have an integer overflow in the bundled Brotli C library

A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library.  Versions of IO::Compress::Brotli prior to 0.007 included a version of the brotli library prior to version 1.0.8, where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your IO::Compress::Brotli module to 0.007 or later. If one cannot update, we recommen

CWE-1395May 30, 2025
CVSS9.8v3.1EPSS0.555%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX