http4k, Unbounded Gzip Decompression Denial of Service, CVE-2026-53659 (High) -DC-Aug2026-1579

Listen to this Post

CVE-2026-53659 is a high-severity denial-of-service (DoS) vulnerability affecting the http4k Kotlin HTTP toolkit. The flaw resides in `ServerFilters.GZip` and RequestFilters.GunZip—filters used to decompress gzip-encoded HTTP request bodies. These filters, along with the underlying gzip functions, imposed no cap on the decompressed size. An attacker can send a small malicious gzip-encoded request body, on the order of kilobytes, which decompresses to gigabytes of data. This process exhausts the JVM heap memory, rendering the server unable to process legitimate requests and effectively denying service to all other clients.
Any http4k server that accepts gzip-encoded requests via these filters is affected. The vulnerability is exploitable by any unauthenticated client, making it particularly dangerous for publicly exposed services. The issue was introduced on August 1, 2017, with commit `2618fe08f9` and remained unpatched for approximately nine years. The fix, released in version 6.49.0.0 (Community Edition) and corresponding LTS versions, caps decompression at 10MB by default. Oversized requests now return a `413 Request Entity Too Large` status, and decompression attempts elsewhere throw a SizeLimitExceededException. The `keyed hmacSHA256` helper and other safe paths remain unaffected. For those unable to upgrade immediately, workarounds include replacing the filters with custom size-limited versions or stripping gzip support at the edge (CDN, reverse proxy, or load balancer).

DailyCVE Form:

Platform: http4k
Version: <=6.48.0.0, <=5.41.0.0, <=4.50.0.0
Vulnerability: Unbounded Gzip Decompression
Severity: High (CVSS 7.5)
date: 2026-06-16

Prediction: Already Patched (2026-05-30)

What Undercode Say:

Analytics of the vulnerability reveal its long-standing presence and potential for widespread impact. The following commands and code snippets illustrate the vulnerable behavior and the implemented fix.

Checking Affected Version:

Check http4k-core version in your project
./gradlew dependencies | grep http4k-core
or for Maven
mvn dependency:tree | grep http4k-core

Vulnerable Filter Usage (Conceptual):

// Vulnerable: No size limit on decompression
val app = ServerFilters.GZip().then { req ->
Response(Status.OK).body(req.bodyString())
}

Fixed Filter Usage:

// Fixed in v6.49.0.0+: Decompression capped at 10MB
val app = ServerFilters.GZip().then { req ->
Response(Status.OK).body(req.bodyString())
}
// Oversized requests now return 413

Exploit: (Educational Purposes!)

A malicious actor can craft a gzip “bomb” – a small compressed payload that decompresses to an enormous size. For example, a few kilobytes of compressed data containing repeated patterns (e.g., long sequences of ‘A’) can expand to gigabytes. Sending such a request to an affected http4k server triggers unbounded decompression, consuming all available JVM heap memory and causing an OutOfMemoryError, which crashes the server or renders it unresponsive.

Protection:

  1. Immediate Upgrade: Update to http4k v6.49.0.0 (Community) or v5.42.0.0 / v4.51.0.0 (Enterprise LTS).
  2. Edge Filtering: If an upgrade is not possible, strip the `Content-Encoding: gzip` header at the edge (CDN, reverse proxy, or load balancer) to prevent gzip-encoded requests from reaching the http4k server.
  3. Custom Filter: Implement a custom GZip/GunZip filter that wraps the `decompressed InputStream` in a size-limited reader, rejecting payloads that exceed a predefined threshold.

Impact

  • Denial of Service: Successful exploitation leads to JVM heap exhaustion, causing the server to become unresponsive and denying service to all legitimate clients.
  • Wide Attack Surface: The vulnerability affects any http4k server using the GZip/GunZip filters and is exploitable by any unauthenticated client.
  • Long Exposure: The flaw existed for approximately nine years, from August 2017 to May 2026, increasing the likelihood of undiscovered exploits in production environments.
  • Availability Impact: The CVSS score of 7.5 reflects a high impact on system availability, with no privileges or user interaction required for exploitation.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top