Denial of Service Vulnerability in Lookyloo by Lookyloo
CVE-2026-66913

6.9MEDIUM

Key Information:

Vendor

Lookyloo

Status
Vendor
CVE Published:
28 July 2026

What is CVE-2026-66913?

The Lookyloo application has a vulnerability that fails to enforce limits on the decompressed size of uploaded capture archives and compressed HAR files. Attackers can exploit this flaw by submitting specially crafted ZIP, gzip, or zlib-compressed uploads, resulting in excessive memory consumption during processing. This can lead to process termination or make the Lookyloo instance unavailable. The issue affects both full capture archive imports and API submissions with gzip-compressed HAR data. Attackers can intentionally trigger repeated exploitation, creating persistent denial-of-service conditions until the processes or the instance are restarted. Recent patches implement a 1 GB cumulative uncompressed-size limitation, enhance size-limited decompression for HAR files, and provide explicit detection for suspected zip bombs.

Affected Version(s)

lookyloo 0 <= 1.40.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Raphael Vinot
https://github.com/EQSTLab
.