High severity7.5NVD Advisory· Published Jun 30, 2026· Updated Jul 2, 2026
CVE-2026-53433
CVE-2026-53433
Description
fzf is vulnerable to a Denial of Service (DoS) due to inefficient HTTP body processing in the --listen mode due to inefficient HTTP body processing using repeated string concatenation, resulting in quadratic time complexity (O(n²)). A crafted POST request with many small segments can trigger excessive CPU usage during request handling.This allows a single malicious request to monopolize the single‑threaded HTTP server, blocking all other clients and resulting in denial of service.
This issue was fixed in version 0.73.1.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/junegunn/fzf/commit/7963a2c6586c0b9eaa89b8995de8f0e08cf8a4cenvdPatch
- cert.pl/en/posts/2026/06/CVE-2026-53432nvdThird Party Advisory
News mentions
0No linked articles in our index yet.