CVE-2026-33241
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
24/03/2026
Last modified:
24/03/2026
Description
Salvo is a Rust web framework. Prior to version 0.89.3, Salvo's form data parsing implementations (`form_data()` method and `Extractible` macro) do not enforce payload size limits before reading request bodies into memory. This allows attackers to cause Out-of-Memory (OOM) conditions by sending extremely large payloads, leading to service crashes and denial of service. Version 0.89.3 contains a patch.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:salvo:salvo:*:*:*:*:*:rust:*:* | 0.89.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



