#VU98715 Resource exhaustion in OkHttp - CVE-2023-3782
Published: October 16, 2024
OkHttp
Square
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability occurs when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can perform MitM to inject a Brotli zip-bomb into an HTTP response. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.