Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CVE-2026-28318 — SolarWinds Serv-U HTTP Deflate Uncontrolled Resource Consumption

Summary

SolarWinds Serv-U's HTTP deflate handler decompresses small POST bodies into gigabytes of memory, crashing the service without authentication. Fixed in 15.5.4 Hotfix 1 and listed in CISA's KEV.
CVE
CVE-2026-28318
Published
Collected

original ↗