VYPR

Bitnami package

brotli

pkg:bitnami/brotli

Vulnerabilities (2)

  • CVE-2020-36846CriMay 30, 2025
    affected < 1.0.8fixed 1.0.8

    A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library.  Versions of IO::Compress::Brotli prior to 0.007 included a version of the brotli library prior to version 1.0.8, where an attacker controlling the input length of a "one-shot" decompression

  • CVE-2020-8927Sep 15, 2020
    affected < 1.0.8fixed 1.0.8

    A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to upda