UNKNOWNhex

gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion

gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion

CVE-2026-43973Published 1 month agoUpdated 2 days agoSource: OSV

Affected packages

  • gun

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
0.38%
EPSS percentile
30.8%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 31%.

gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion | HackTribune