—Hex
EEF-CVE-2026-49755· CVE-2026-49755, GHSA-655f-mp8p-96gvDecompression bomb DoS in Req via auto-decoded archive and compressed response bodies
Modified: 9/8/2026
package
pkg:hex/req
Decompression bomb DoS in Req via auto-decoded archive and compressed response bodies
Modified: 9/8/2026
Multipart form-data header injection in Req via unescaped name/filename/content_type
Modified: 9/8/2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
Modified: 7/29/2026
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
Modified: 7/29/2026