CVE-2026-40036
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
08/04/2026
Last modified:
17/04/2026
Description
Unfurl before 2026.04 contains an unbounded zlib decompression vulnerability in parse_compressed.py that allows remote attackers to cause denial of service. Attackers can submit highly compressed payloads via URL parameters to the /json/visjs endpoint that expand to gigabytes, exhausting server memory and crashing the service.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ryandfir:unfurl:*:*:*:*:*:*:*:* | 2026.04 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



