CVE-2026-44981

NONE
CVSS v3
CVSS v2
0.29% EPSS (exploit probability)
CWE-409CWE

Description

CrowdSec offers crowdsourced protection against malicious IPs. From 1.7.0 until 1.7.8, the LAPI router used gin-contrib/gzip with DefaultDecompressHandle globally in pkg/apiserver/controllers/controller.go, causing /v1/watchers and /v1/watchers/login to decompress unauthenticated gzip-compressed JSON request bodies without enforcing a maximum decompressed size and allowing excessive heap allocation that can make LAPI unreachable. This issue is fixed in version 1.7.8.

Affected routers (0)

No routers currently mapped to this CVE in our database.

External references