216.73.217.22

CVE-2026-33241

· Published 24/03/2026 00:16 · Modified 24/03/2026 19:37

Labels: CVE-2026-33241 2026-03-24CVE-2026-33241CWE-770[email protected]

Essential information

Published
24/03/2026 00:16
Modified
24/03/2026 19:37
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Salvo is a Rust web framework. Prior to version 0.89.3, Salvo's form data parsing implementations (`form_data()` method and `Extractible` macro) do not enforce payload size limits before reading request bodies into memory. This allows attackers to cause Out-of-Memory (OOM) conditions by sending extremely large payloads, leading to service crashes and denial of service. Version 0.89.3 contains a patch.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
salvo / salvo cpe:2.3:a:salvo:salvo:*:*:*:*:*:rust:*:*

References