req
Req is a batteries-included HTTP client for Elixir.
Activity
- Latest release
- 2d ago
- Total releases
- 59
- Cadence
- ~14 days
- Last 12 months
- 9
Reach
- Stars
- 1.3k
Details
- License
- Apache-2.0
- First release
- Jul 15, 2021
| Version | Released | |
|---|---|---|
0.7.1
patch
| ||
0.7.0
minor
| ||
0.6.3
patch
| ||
0.6.2
patch
| ||
0.6.1
patch
| ||
0.6.0
minor
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.5.18
patch
2 CVEs
CVE-2026-49756
GHSA-px9f-whj3-246m
EEF-CVE-2026-49756
Jul 29, 2026
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
Medium
Network
Low
None
None
SummaryReq's multipart form encoder interpolates the per-part Details
The flaw is reachable through every supported way of supplying a part. It is especially easy to hit when PoC
ImpactHTTP request smuggling / multipart parameter smuggling in the HTTP client. Any application using Req to send Affected versions
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.3
0.5.4
0.5.5
+ 4 more Show less
0.5.6
0.5.7
0.5.8
0.5.9
Fixed in
0.6.0
References
Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.5.17
patch
2 CVEs
CVE-2026-49756
GHSA-px9f-whj3-246m
EEF-CVE-2026-49756
Jul 29, 2026
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
Medium
Network
Low
None
None
SummaryReq's multipart form encoder interpolates the per-part Details
The flaw is reachable through every supported way of supplying a part. It is especially easy to hit when PoC
ImpactHTTP request smuggling / multipart parameter smuggling in the HTTP client. Any application using Req to send Affected versions
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.3
0.5.4
0.5.5
+ 4 more Show less
0.5.6
0.5.7
0.5.8
0.5.9
Fixed in
0.6.0
References
Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.5.16
patch
2 CVEs
CVE-2026-49756
GHSA-px9f-whj3-246m
EEF-CVE-2026-49756
Jul 29, 2026
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
Medium
Network
Low
None
None
SummaryReq's multipart form encoder interpolates the per-part Details
The flaw is reachable through every supported way of supplying a part. It is especially easy to hit when PoC
ImpactHTTP request smuggling / multipart parameter smuggling in the HTTP client. Any application using Req to send Affected versions
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.3
0.5.4
0.5.5
+ 4 more Show less
0.5.6
0.5.7
0.5.8
0.5.9
Fixed in
0.6.0
References
Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.5.15
patch
2 CVEs
CVE-2026-49756
GHSA-px9f-whj3-246m
EEF-CVE-2026-49756
Jul 29, 2026
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
Medium
Network
Low
None
None
SummaryReq's multipart form encoder interpolates the per-part Details
The flaw is reachable through every supported way of supplying a part. It is especially easy to hit when PoC
ImpactHTTP request smuggling / multipart parameter smuggling in the HTTP client. Any application using Req to send Affected versions
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.3
0.5.4
0.5.5
+ 4 more Show less
0.5.6
0.5.7
0.5.8
0.5.9
Fixed in
0.6.0
References
Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.5.14
patch
2 CVEs
CVE-2026-49756
GHSA-px9f-whj3-246m
EEF-CVE-2026-49756
Jul 29, 2026
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
Medium
Network
Low
None
None
SummaryReq's multipart form encoder interpolates the per-part Details
The flaw is reachable through every supported way of supplying a part. It is especially easy to hit when PoC
ImpactHTTP request smuggling / multipart parameter smuggling in the HTTP client. Any application using Req to send Affected versions
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.3
0.5.4
0.5.5
+ 4 more Show less
0.5.6
0.5.7
0.5.8
0.5.9
Fixed in
0.6.0
References
Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.5.13
patch
2 CVEs
CVE-2026-49756
GHSA-px9f-whj3-246m
EEF-CVE-2026-49756
Jul 29, 2026
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
Medium
Network
Low
None
None
SummaryReq's multipart form encoder interpolates the per-part Details
The flaw is reachable through every supported way of supplying a part. It is especially easy to hit when PoC
ImpactHTTP request smuggling / multipart parameter smuggling in the HTTP client. Any application using Req to send Affected versions
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.3
0.5.4
0.5.5
+ 4 more Show less
0.5.6
0.5.7
0.5.8
0.5.9
Fixed in
0.6.0
References
Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.5.12
patch
2 CVEs
CVE-2026-49756
GHSA-px9f-whj3-246m
EEF-CVE-2026-49756
Jul 29, 2026
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
Medium
Network
Low
None
None
SummaryReq's multipart form encoder interpolates the per-part Details
The flaw is reachable through every supported way of supplying a part. It is especially easy to hit when PoC
ImpactHTTP request smuggling / multipart parameter smuggling in the HTTP client. Any application using Req to send Affected versions
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.3
0.5.4
0.5.5
+ 4 more Show less
0.5.6
0.5.7
0.5.8
0.5.9
Fixed in
0.6.0
References
Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.5.11
patch
2 CVEs
CVE-2026-49756
GHSA-px9f-whj3-246m
EEF-CVE-2026-49756
Jul 29, 2026
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
Medium
Network
Low
None
None
SummaryReq's multipart form encoder interpolates the per-part Details
The flaw is reachable through every supported way of supplying a part. It is especially easy to hit when PoC
ImpactHTTP request smuggling / multipart parameter smuggling in the HTTP client. Any application using Req to send Affected versions
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.3
0.5.4
0.5.5
+ 4 more Show less
0.5.6
0.5.7
0.5.8
0.5.9
Fixed in
0.6.0
References
Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.5.10
patch
2 CVEs
CVE-2026-49756
GHSA-px9f-whj3-246m
EEF-CVE-2026-49756
Jul 29, 2026
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
Medium
Network
Low
None
None
SummaryReq's multipart form encoder interpolates the per-part Details
The flaw is reachable through every supported way of supplying a part. It is especially easy to hit when PoC
ImpactHTTP request smuggling / multipart parameter smuggling in the HTTP client. Any application using Req to send Affected versions
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.3
0.5.4
0.5.5
+ 4 more Show less
0.5.6
0.5.7
0.5.8
0.5.9
Fixed in
0.6.0
References
Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.5.9
patch
2 CVEs
CVE-2026-49756
GHSA-px9f-whj3-246m
EEF-CVE-2026-49756
Jul 29, 2026
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
Medium
Network
Low
None
None
SummaryReq's multipart form encoder interpolates the per-part Details
The flaw is reachable through every supported way of supplying a part. It is especially easy to hit when PoC
ImpactHTTP request smuggling / multipart parameter smuggling in the HTTP client. Any application using Req to send Affected versions
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.3
0.5.4
0.5.5
+ 4 more Show less
0.5.6
0.5.7
0.5.8
0.5.9
Fixed in
0.6.0
References
Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.5.8
patch
2 CVEs
CVE-2026-49756
GHSA-px9f-whj3-246m
EEF-CVE-2026-49756
Jul 29, 2026
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
Medium
Network
Low
None
None
SummaryReq's multipart form encoder interpolates the per-part Details
The flaw is reachable through every supported way of supplying a part. It is especially easy to hit when PoC
ImpactHTTP request smuggling / multipart parameter smuggling in the HTTP client. Any application using Req to send Affected versions
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.3
0.5.4
0.5.5
+ 4 more Show less
0.5.6
0.5.7
0.5.8
0.5.9
Fixed in
0.6.0
References
Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.5.7
patch
2 CVEs
CVE-2026-49756
GHSA-px9f-whj3-246m
EEF-CVE-2026-49756
Jul 29, 2026
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
Medium
Network
Low
None
None
SummaryReq's multipart form encoder interpolates the per-part Details
The flaw is reachable through every supported way of supplying a part. It is especially easy to hit when PoC
ImpactHTTP request smuggling / multipart parameter smuggling in the HTTP client. Any application using Req to send Affected versions
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.3
0.5.4
0.5.5
+ 4 more Show less
0.5.6
0.5.7
0.5.8
0.5.9
Fixed in
0.6.0
References
Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.5.6
patch
2 CVEs
CVE-2026-49756
GHSA-px9f-whj3-246m
EEF-CVE-2026-49756
Jul 29, 2026
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
Medium
Network
Low
None
None
SummaryReq's multipart form encoder interpolates the per-part Details
The flaw is reachable through every supported way of supplying a part. It is especially easy to hit when PoC
ImpactHTTP request smuggling / multipart parameter smuggling in the HTTP client. Any application using Req to send Affected versions
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.3
0.5.4
0.5.5
+ 4 more Show less
0.5.6
0.5.7
0.5.8
0.5.9
Fixed in
0.6.0
References
Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.5.5
patch
2 CVEs
CVE-2026-49756
GHSA-px9f-whj3-246m
EEF-CVE-2026-49756
Jul 29, 2026
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
Medium
Network
Low
None
None
SummaryReq's multipart form encoder interpolates the per-part Details
The flaw is reachable through every supported way of supplying a part. It is especially easy to hit when PoC
ImpactHTTP request smuggling / multipart parameter smuggling in the HTTP client. Any application using Req to send Affected versions
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.3
0.5.4
0.5.5
+ 4 more Show less
0.5.6
0.5.7
0.5.8
0.5.9
Fixed in
0.6.0
References
Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.5.4
patch
2 CVEs
CVE-2026-49756
GHSA-px9f-whj3-246m
EEF-CVE-2026-49756
Jul 29, 2026
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
Medium
Network
Low
None
None
SummaryReq's multipart form encoder interpolates the per-part Details
The flaw is reachable through every supported way of supplying a part. It is especially easy to hit when PoC
ImpactHTTP request smuggling / multipart parameter smuggling in the HTTP client. Any application using Req to send Affected versions
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.3
0.5.4
0.5.5
+ 4 more Show less
0.5.6
0.5.7
0.5.8
0.5.9
Fixed in
0.6.0
References
Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.5.3
patch
2 CVEs
CVE-2026-49756
GHSA-px9f-whj3-246m
EEF-CVE-2026-49756
Jul 29, 2026
Req vulnerable to multipart form-data header injection via unescaped name/filename/content_type
Medium
Network
Low
None
None
SummaryReq's multipart form encoder interpolates the per-part Details
The flaw is reachable through every supported way of supplying a part. It is especially easy to hit when PoC
ImpactHTTP request smuggling / multipart parameter smuggling in the HTTP client. Any application using Req to send Affected versions
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.3
0.5.4
0.5.5
+ 4 more Show less
0.5.6
0.5.7
0.5.8
0.5.9
Fixed in
0.6.0
References
Updated Jul 29, 2026 · Source: OSV.dev
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.5.2
patch
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.5.1
patch
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.5.0
minor
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.4.14
patch
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev |
0.4.14
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
0.4.13
patch
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.4.12
patch
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.4.11
patch
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.4.10
patch
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.4.9
patch
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.4.8
patch
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.4.7
patch
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.4.6
patch
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.4.5
patch
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.4.4
patch
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.3.12
patch
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.4.3
patch
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.4.2
patch
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.4.1
patch
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.4.0
minor
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.3.11
patch
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.3.10
patch
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.3.9
patch
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.3.8
patch
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.3.7
patch
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.3.6
patch
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.3.5
patch
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.3.4
patch
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev | ||
0.3.3
patch
1 CVE
CVE-2026-49755
GHSA-655f-mp8p-96gv
EEF-CVE-2026-49755
Jul 29, 2026
Req vulnerable to unbounded archive/compression extraction triggered by response content-type
High
Network
Low
None
None
SummaryReq's default response pipeline auto-decodes archive and compressed bodies based on the server-supplied Details1. Archive auto-decoding. 2. content-encoding chaining. 3. Default-on, attacker-chosen decoder. Both steps are part of Req's default pipeline. The caller does not need to opt in, and the attacker chooses which decoder fires by setting PoC
ImpactMemory-exhaustion denial of service against any Elixir application that uses Req with its default step pipeline to fetch URLs influenced by an untrusted party, including webhook senders, link previews, OAuth/OIDC discovery clients, package mirrors, image proxies, and any Affected versions
0.1.0
0.1.1
0.1.2
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.2
+ 42 more Show less
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.11
0.4.12
0.4.13
0.4.14
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.5.0
0.5.1
0.5.10
0.5.11
0.5.12
0.5.13
0.5.14
0.5.15
0.5.16
0.5.17
0.5.18
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.5.9
0.6.0
Fixed in
0.6.1
References
Updated Jul 29, 2026 · Source: OSV.dev |