Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-48594— Decompression bomb in Tesla.Middleware.DecompressResponse and Tesla.Middleware.Compression

Quick assessment

Affected
elixir-tesla tesla
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Tesla是Elixir Tesla开源的一个HTTP客户端软件。 Tesla 0.6.0版本至1.18.3之前版本存在安全漏洞,该漏洞源于处理高度压缩数据时未限制解压大小,可能导致通过HTTP响应体中的解压炸弹造成拒绝服务。

AI Predicted 7.5 Difficulty: Easy EPSS 0.46% · P38

Possible ATT&CK Techniques 1 AI

T1496 · Resource Hijacking

Affected Version Matrix 2

VendorProduct Version RangeStatus
elixir-tesla tesla 0.6.0< 1.18.3 affected
5bd90bb5cf0d15e375edc2a66fa322292940fce2< 340f75b5d191dc747ef7ac6365bd002d1cd55a9d affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-48594

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Decompression bomb in Tesla.Middleware.DecompressResponse and Tesla.Middleware.Compression
Source: CVE Program / CVE List V5
Vulnerability Description
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-tesla tesla allows a denial of service via decompression bomb in HTTP response bodies. When Tesla.Middleware.DecompressResponse or Tesla.Middleware.Compression is included in a Tesla middleware pipeline, HTTP response bodies are decompressed eagerly with no size limit. The decompress_body/2 function in lib/tesla/middleware/compression.ex passes the entire response body to :zlib.gunzip/1 or :zlib.unzip/1 without any cap on the output size. Additionally, compression_algorithms/1 splits the content-encoding header on commas and decompress_body/2 recurses once per token, applying a decompression pass on each iteration. A server advertising content-encoding: gzip, gzip, gzip, gzip causes four recursive decompression passes, yielding exponential amplification: each gzip layer can expand its input roughly 1000x, so a payload of a few hundred bytes on the wire inflates to gigabytes of BEAM heap, exhausting memory and crashing or freezing the calling process. This issue affects tesla: from 0.6.0 before 1.18.3.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
对高度压缩数据的处理不恰当(数据放大攻击)
Source: CVE Program / CVE List V5
Vulnerability Title
Tesla 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Tesla是Elixir Tesla开源的一个HTTP客户端软件。 Tesla 0.6.0版本至1.18.3之前版本存在安全漏洞,该漏洞源于处理高度压缩数据时未限制解压大小,可能导致通过HTTP响应体中的解压炸弹造成拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
elixir-tesla tesla 0.6.0 ~ 1.18.3 cpe:2.3:a:elixir-tesla:tesla:*:*:*:*:*:*:*:*
elixir-tesla tesla 5bd90bb5cf0d15e375edc2a66fa322292940fce2 ~ 340f75b5d191dc747ef7ac6365bd002d1cd55a9d cpe:2.3:a:elixir-tesla:tesla:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-48594

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-48594

登录查看更多情报信息。

Patches & Fixes for CVE-2026-48594 (1)

Vendor Advisories for CVE-2026-48594 (2)

Other References for CVE-2026-48594 (1)

Same Patch Batch · elixir-tesla · 2026-06-02 · 5 CVEs total

CVE-2026-48598 CRLF injection in Tesla.Multipart disposition parameters allows multipart part header inje
CVE-2026-48596 CRLF injection in Tesla.Multipart.add_content_type_param/2 allows HTTP header injection
CVE-2026-48595 Authorization header leaks to third-party origin on cross-origin redirect in Tesla.Middlew
CVE-2026-48597 Atom table exhaustion via untrusted URL scheme in Tesla.Adapter.Mint

IV. Related Vulnerabilities

V. Comments for CVE-2026-48594

No comments yet


Leave a comment