Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): through <=2.2.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue.
The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.
Link | Tags |
---|---|
https://lists.apache.org/thread/grn0x8tmssx07qc9z50lwgmrkwzrrhzg | vendor advisory mailing list |
http://www.openwall.com/lists/oss-security/2025/03/19/6 | mailing list third party advisory |