Due to support of Gzip compression in request bodies, as well as a lack of limiting response body sizes, a malicious server can cause a client to consume a significant amount of system resources, which may be used as a denial of service vector.
{ "github_reviewed_at": "2022-12-30T19:15:32Z", "github_reviewed": true, "nvd_published_at": "2022-12-27T22:15:00Z", "cwe_ids": [ "CWE-400" ], "severity": "HIGH" }