#VU80783 Incorrect Conversion between Numeric Types in Okio - CVE-2023-3635
Published: September 14, 2023 / Updated: January 22, 2026
Okio
Square
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to GzipSource does not handle an exception that might be raised when parsing a malformed gzip buffer. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.