We found results for “”
CVE-2020-36846
Good to know:
Date: May 29, 2025
A buffer overflow, as described in CVE-2020-8927, exists in the embedded Brotli library. Versions of IO::Compress::Brotli prior to 0.007 included a version of the brotli library prior to version 1.0.8, where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your IO::Compress::Brotli module to 0.007 or later. If one cannot update, we recommend to use the "streaming" API as opposed to the "one-shot" API, and impose chunk size limits.
Severity Score
Related Resources (37)
Severity Score
Weakness Type (CWE)
Top Fix
Upgrade Version
Upgrade to version microsoft.netcore.app.runtime.linux-arm - 3.1.23;microsoft.netcore.app.runtime.linux-arm - 5.0.15;microsoft.netcore.app.runtime.linux-arm - 6.0.3;microsoft.netcore.app.runtime.linux-arm64 - 3.1.23;microsoft.netcore.app.runtime.linux-arm64 - 5.0.15;microsoft.netcore.app.runtime.linux-arm64 - 6.0.3;microsoft.netcore.app.runtime.linux-musl-arm64 - 3.1.23;microsoft.netcore.app.runtime.linux-musl-arm64 - 5.0.15;microsoft.netcore.app.runtime.linux-musl-arm64 - 6.0.3;microsoft.netcore.app.runtime.linux-x64 - 3.1.23;microsoft.netcore.app.runtime.linux-x64 - 5.0.15;microsoft.netcore.app.runtime.linux-x64 - 6.0.3;microsoft.netcore.app.runtime.osx-x64 - 3.1.23;microsoft.netcore.app.runtime.osx-x64 - 5.0.15;microsoft.netcore.app.runtime.osx-x64 - 6.0.3;microsoft.netcore.app.runtime.win-arm - 3.1.23;microsoft.netcore.app.runtime.win-arm - 5.0.15;microsoft.netcore.app.runtime.win-arm - 6.0.3;microsoft.netcore.app.runtime.win-arm64 - 3.1.23;microsoft.netcore.app.runtime.win-arm64 - 5.0.15;microsoft.netcore.app.runtime.win-arm64 - 6.0.3;microsoft.netcore.app.runtime.win-x64 - 3.1.23;microsoft.netcore.app.runtime.win-x64 - 5.0.15;microsoft.netcore.app.runtime.win-x64 - 6.0.3;microsoft.netcore.app.runtime.win-x86 - 3.1.23;microsoft.netcore.app.runtime.win-x86 - 5.0.15;microsoft.netcore.app.runtime.win-x86 - 6.0.3;microsoft.netcore.app.runtime.mono.llvm.aot.linux-arm64 - 5.0.15;microsoft.netcore.app.runtime.mono.llvm.aot.linux-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.llvm.aot.linux-x64 - 5.0.15;microsoft.netcore.app.runtime.mono.llvm.aot.linux-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.llvm.aot.osx-x64 - 5.0.15;microsoft.netcore.app.runtime.mono.llvm.aot.osx-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.llvm.linux-arm64 - 5.0.15;microsoft.netcore.app.runtime.mono.llvm.linux-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.llvm.linux-x64 - 5.0.15;microsoft.netcore.app.runtime.mono.llvm.linux-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.llvm.osx-x64 - 5.0.15;microsoft.netcore.app.runtime.mono.llvm.osx-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.linux-arm - 5.0.15;microsoft.netcore.app.runtime.mono.linux-arm - 6.0.3;microsoft.netcore.app.runtime.mono.linux-arm64 - 5.0.15;microsoft.netcore.app.runtime.mono.linux-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.linux-musl-x64 - 5.0.15;microsoft.netcore.app.runtime.mono.linux-musl-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.linux-x64 - 5.0.15;microsoft.netcore.app.runtime.mono.linux-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.osx-x64 - 5.0.15;microsoft.netcore.app.runtime.mono.osx-x64 - 6.0.3;microsoft.netcore.app.runtime.browser-wasm - 5.0.15;microsoft.netcore.app.runtime.linux-musl-arm - 5.0.15;microsoft.netcore.app.runtime.linux-musl-arm - 6.0.3;microsoft.netcore.app.runtime.linux-musl-x64 - 5.0.15;microsoft.netcore.app.runtime.linux-musl-x64 - 6.0.3;microsoft.netcore.app.runtime.aot.linux-x64.cross.android-arm - 6.0.3;microsoft.netcore.app.runtime.aot.linux-x64.cross.android-arm64 - 6.0.3;microsoft.netcore.app.runtime.aot.linux-x64.cross.android-x64 - 6.0.3;microsoft.netcore.app.runtime.aot.linux-x64.cross.android-x86 - 6.0.3;microsoft.netcore.app.runtime.aot.linux-x64.cross.browser-wasm - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.android-arm - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.android-arm64 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.android-x64 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.android-x86 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.browser-wasm - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.ios-arm - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.ios-arm64 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.iossimulator-arm64 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.iossimulator-x64 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.iossimulator-x86 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.maccatalyst-arm64 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.maccatalyst-x64 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.tvos-arm64 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.tvossimulator-arm64 - 6.0.3;microsoft.netcore.app.runtime.aot.osx-x64.cross.tvossimulator-x64 - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.android-arm - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.android-arm.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.android-arm64 - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.android-arm64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.android-x64 - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.android-x64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.android-x86 - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.android-x86.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.browser-wasm - 6.0.3;microsoft.netcore.app.runtime.aot.win-x64.cross.browser-wasm.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-arm - 6.0.3;microsoft.netcore.app.runtime.mono.android-arm.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-arm.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-arm.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.android-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-arm64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-arm64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-arm64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.android-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-x64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-x64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-x64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.android-x86 - 6.0.3;microsoft.netcore.app.runtime.mono.android-x86.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-x86.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.android-x86.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.browser-wasm - 6.0.3;microsoft.netcore.app.runtime.mono.browser-wasm.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.browser-wasm.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.browser-wasm.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.ios-arm - 6.0.3;microsoft.netcore.app.runtime.mono.ios-arm.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.ios-arm.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.ios-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.ios-arm64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.ios-arm64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.ios-arm64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-arm64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-arm64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-arm64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-x64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-x64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-x64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-x86 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-x86.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-x86.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.iossimulator-x86.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.maccatalyst-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.maccatalyst-arm64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.maccatalyst-arm64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.maccatalyst-arm64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.maccatalyst-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.maccatalyst-x64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.maccatalyst-x64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.maccatalyst-x64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.osx-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvos-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvos-arm64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvos-arm64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvos-arm64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.tvossimulator-arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvossimulator-arm64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvossimulator-arm64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvossimulator-arm64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.tvossimulator-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvossimulator-x64.msi.arm64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvossimulator-x64.msi.x64 - 6.0.3;microsoft.netcore.app.runtime.mono.tvossimulator-x64.msi.x86 - 6.0.3;microsoft.netcore.app.runtime.mono.win-x64 - 6.0.3;microsoft.netcore.app.runtime.mono.win-x86 - 6.0.3;microsoft.netcore.app.runtime.osx-arm64 - 6.0.3;brotli - 1.0.8
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


