Denial of Service Vulnerability in Lookyloo by Lookyloo
CVE-2026-66913
What is CVE-2026-66913?
The Lookyloo application has a vulnerability that fails to enforce limits on the decompressed size of uploaded capture archives and compressed HAR files. Attackers can exploit this flaw by submitting specially crafted ZIP, gzip, or zlib-compressed uploads, resulting in excessive memory consumption during processing. This can lead to process termination or make the Lookyloo instance unavailable. The issue affects both full capture archive imports and API submissions with gzip-compressed HAR data. Attackers can intentionally trigger repeated exploitation, creating persistent denial-of-service conditions until the processes or the instance are restarted. Recent patches implement a 1 GB cumulative uncompressed-size limitation, enhance size-limited decompression for HAR files, and provide explicit detection for suspected zip bombs.
Affected Version(s)
lookyloo 0 <= 1.40.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
