dfir-unfurl
Unfurl takes a URL and expands ("unfurls") it into a directed graph
Activity
- Latest release
- 5mo ago
- Total releases
- 28
- Cadence
- ~13 days
- Last 12 months
- 1
Details
- License
- custom
- First release
- Jun 30, 2020
| Version | Released | |
|---|---|---|
20260405
unknown
|
20260405
unknown
Dependencies (17)
+ 9 more |
|
20250810
unknown
2 CVEs
CVE-2026-40036
PYSEC-2026-1294
GHSA-h5qv-qjv4-pc5m
Jul 07, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
Network
Low
None
None
SummaryThe compressed data parser uses Details
PoC
PoC Script
ImpactA remote, unauthenticated attacker can cause high memory usage and potentially crash the service. The impact depends on deployment limits (process memory, URL length limits, and request size limits). Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
Fixed in
20260405
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-40035
GHSA-vg9h-jx4v-cwx2
Jan 29, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
Network
Low
None
None
SummaryThe Unfurl web app enables Flask debug mode even when configuration sets Details
PoC
PoC Script (inline)
ImpactIf the service is exposed beyond localhost (bound to 0.0.0.0 or reverse-proxied), an attacker can access the Werkzeug debugger. This can disclose sensitive information and may allow remote code execution if a debugger PIN is obtained. At minimum, stack traces and environment details are exposed on errors. Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
References Updated Jul 08, 2026 · Source: OSV.dev |
20250810
unknown
Dependencies (16)
+ 8 more |
|
20250312
unknown
2 CVEs
CVE-2026-40036
PYSEC-2026-1294
GHSA-h5qv-qjv4-pc5m
Jul 07, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
Network
Low
None
None
SummaryThe compressed data parser uses Details
PoC
PoC Script
ImpactA remote, unauthenticated attacker can cause high memory usage and potentially crash the service. The impact depends on deployment limits (process memory, URL length limits, and request size limits). Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
Fixed in
20260405
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-40035
GHSA-vg9h-jx4v-cwx2
Jan 29, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
Network
Low
None
None
SummaryThe Unfurl web app enables Flask debug mode even when configuration sets Details
PoC
PoC Script (inline)
ImpactIf the service is exposed beyond localhost (bound to 0.0.0.0 or reverse-proxied), an attacker can access the Werkzeug debugger. This can disclose sensitive information and may allow remote code execution if a debugger PIN is obtained. At minimum, stack traces and environment details are exposed on errors. Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
References Updated Jul 08, 2026 · Source: OSV.dev |
20250312
unknown
Dependencies (16)
+ 8 more |
|
20250218
unknown
2 CVEs
CVE-2026-40036
PYSEC-2026-1294
GHSA-h5qv-qjv4-pc5m
Jul 07, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
Network
Low
None
None
SummaryThe compressed data parser uses Details
PoC
PoC Script
ImpactA remote, unauthenticated attacker can cause high memory usage and potentially crash the service. The impact depends on deployment limits (process memory, URL length limits, and request size limits). Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
Fixed in
20260405
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-40035
GHSA-vg9h-jx4v-cwx2
Jan 29, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
Network
Low
None
None
SummaryThe Unfurl web app enables Flask debug mode even when configuration sets Details
PoC
PoC Script (inline)
ImpactIf the service is exposed beyond localhost (bound to 0.0.0.0 or reverse-proxied), an attacker can access the Werkzeug debugger. This can disclose sensitive information and may allow remote code execution if a debugger PIN is obtained. At minimum, stack traces and environment details are exposed on errors. Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
References Updated Jul 08, 2026 · Source: OSV.dev |
20250218
unknown
Dependencies (16)
+ 8 more |
|
20241121
unknown
2 CVEs
CVE-2026-40036
PYSEC-2026-1294
GHSA-h5qv-qjv4-pc5m
Jul 07, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
Network
Low
None
None
SummaryThe compressed data parser uses Details
PoC
PoC Script
ImpactA remote, unauthenticated attacker can cause high memory usage and potentially crash the service. The impact depends on deployment limits (process memory, URL length limits, and request size limits). Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
Fixed in
20260405
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-40035
GHSA-vg9h-jx4v-cwx2
Jan 29, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
Network
Low
None
None
SummaryThe Unfurl web app enables Flask debug mode even when configuration sets Details
PoC
PoC Script (inline)
ImpactIf the service is exposed beyond localhost (bound to 0.0.0.0 or reverse-proxied), an attacker can access the Werkzeug debugger. This can disclose sensitive information and may allow remote code execution if a debugger PIN is obtained. At minimum, stack traces and environment details are exposed on errors. Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
References Updated Jul 08, 2026 · Source: OSV.dev |
20241121
unknown
Dependencies (16)
+ 8 more |
|
20241120
unknown
2 CVEs
CVE-2026-40036
PYSEC-2026-1294
GHSA-h5qv-qjv4-pc5m
Jul 07, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
Network
Low
None
None
SummaryThe compressed data parser uses Details
PoC
PoC Script
ImpactA remote, unauthenticated attacker can cause high memory usage and potentially crash the service. The impact depends on deployment limits (process memory, URL length limits, and request size limits). Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
Fixed in
20260405
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-40035
GHSA-vg9h-jx4v-cwx2
Jan 29, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
Network
Low
None
None
SummaryThe Unfurl web app enables Flask debug mode even when configuration sets Details
PoC
PoC Script (inline)
ImpactIf the service is exposed beyond localhost (bound to 0.0.0.0 or reverse-proxied), an attacker can access the Werkzeug debugger. This can disclose sensitive information and may allow remote code execution if a debugger PIN is obtained. At minimum, stack traces and environment details are exposed on errors. Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
References Updated Jul 08, 2026 · Source: OSV.dev |
20241120
unknown
Dependencies (16)
+ 8 more |
|
20240627
unknown
2 CVEs
CVE-2026-40036
PYSEC-2026-1294
GHSA-h5qv-qjv4-pc5m
Jul 07, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
Network
Low
None
None
SummaryThe compressed data parser uses Details
PoC
PoC Script
ImpactA remote, unauthenticated attacker can cause high memory usage and potentially crash the service. The impact depends on deployment limits (process memory, URL length limits, and request size limits). Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
Fixed in
20260405
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-40035
GHSA-vg9h-jx4v-cwx2
Jan 29, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
Network
Low
None
None
SummaryThe Unfurl web app enables Flask debug mode even when configuration sets Details
PoC
PoC Script (inline)
ImpactIf the service is exposed beyond localhost (bound to 0.0.0.0 or reverse-proxied), an attacker can access the Werkzeug debugger. This can disclose sensitive information and may allow remote code execution if a debugger PIN is obtained. At minimum, stack traces and environment details are exposed on errors. Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
References Updated Jul 08, 2026 · Source: OSV.dev |
20240627
unknown
Dependencies (15)
+ 7 more |
|
20240626
unknown
2 CVEs
CVE-2026-40036
PYSEC-2026-1294
GHSA-h5qv-qjv4-pc5m
Jul 07, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
Network
Low
None
None
SummaryThe compressed data parser uses Details
PoC
PoC Script
ImpactA remote, unauthenticated attacker can cause high memory usage and potentially crash the service. The impact depends on deployment limits (process memory, URL length limits, and request size limits). Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
Fixed in
20260405
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-40035
GHSA-vg9h-jx4v-cwx2
Jan 29, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
Network
Low
None
None
SummaryThe Unfurl web app enables Flask debug mode even when configuration sets Details
PoC
PoC Script (inline)
ImpactIf the service is exposed beyond localhost (bound to 0.0.0.0 or reverse-proxied), an attacker can access the Werkzeug debugger. This can disclose sensitive information and may allow remote code execution if a debugger PIN is obtained. At minimum, stack traces and environment details are exposed on errors. Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
References Updated Jul 08, 2026 · Source: OSV.dev |
20240626
unknown
Dependencies (15)
+ 7 more |
|
20240625
unknown
2 CVEs
CVE-2026-40036
PYSEC-2026-1294
GHSA-h5qv-qjv4-pc5m
Jul 07, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
Network
Low
None
None
SummaryThe compressed data parser uses Details
PoC
PoC Script
ImpactA remote, unauthenticated attacker can cause high memory usage and potentially crash the service. The impact depends on deployment limits (process memory, URL length limits, and request size limits). Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
Fixed in
20260405
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-40035
GHSA-vg9h-jx4v-cwx2
Jan 29, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
Network
Low
None
None
SummaryThe Unfurl web app enables Flask debug mode even when configuration sets Details
PoC
PoC Script (inline)
ImpactIf the service is exposed beyond localhost (bound to 0.0.0.0 or reverse-proxied), an attacker can access the Werkzeug debugger. This can disclose sensitive information and may allow remote code execution if a debugger PIN is obtained. At minimum, stack traces and environment details are exposed on errors. Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
References Updated Jul 08, 2026 · Source: OSV.dev |
20240625
unknown
Dependencies (15)
+ 7 more |
|
20230901
unknown
2 CVEs
CVE-2026-40036
PYSEC-2026-1294
GHSA-h5qv-qjv4-pc5m
Jul 07, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
Network
Low
None
None
SummaryThe compressed data parser uses Details
PoC
PoC Script
ImpactA remote, unauthenticated attacker can cause high memory usage and potentially crash the service. The impact depends on deployment limits (process memory, URL length limits, and request size limits). Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
Fixed in
20260405
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-40035
GHSA-vg9h-jx4v-cwx2
Jan 29, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
Network
Low
None
None
SummaryThe Unfurl web app enables Flask debug mode even when configuration sets Details
PoC
PoC Script (inline)
ImpactIf the service is exposed beyond localhost (bound to 0.0.0.0 or reverse-proxied), an attacker can access the Werkzeug debugger. This can disclose sensitive information and may allow remote code execution if a debugger PIN is obtained. At minimum, stack traces and environment details are exposed on errors. Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
References Updated Jul 08, 2026 · Source: OSV.dev |
20230901
unknown
Dependencies (14)
+ 6 more |
|
20230900
unknown
2 CVEs
CVE-2026-40036
PYSEC-2026-1294
GHSA-h5qv-qjv4-pc5m
Jul 07, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
Network
Low
None
None
SummaryThe compressed data parser uses Details
PoC
PoC Script
ImpactA remote, unauthenticated attacker can cause high memory usage and potentially crash the service. The impact depends on deployment limits (process memory, URL length limits, and request size limits). Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
Fixed in
20260405
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-40035
GHSA-vg9h-jx4v-cwx2
Jan 29, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
Network
Low
None
None
SummaryThe Unfurl web app enables Flask debug mode even when configuration sets Details
PoC
PoC Script (inline)
ImpactIf the service is exposed beyond localhost (bound to 0.0.0.0 or reverse-proxied), an attacker can access the Werkzeug debugger. This can disclose sensitive information and may allow remote code execution if a debugger PIN is obtained. At minimum, stack traces and environment details are exposed on errors. Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
References Updated Jul 08, 2026 · Source: OSV.dev |
20230900
unknown
Dependencies (13)
+ 5 more |
|
20221100
unknown
2 CVEs
CVE-2026-40036
PYSEC-2026-1294
GHSA-h5qv-qjv4-pc5m
Jul 07, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
Network
Low
None
None
SummaryThe compressed data parser uses Details
PoC
PoC Script
ImpactA remote, unauthenticated attacker can cause high memory usage and potentially crash the service. The impact depends on deployment limits (process memory, URL length limits, and request size limits). Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
Fixed in
20260405
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-40035
GHSA-vg9h-jx4v-cwx2
Jan 29, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
Network
Low
None
None
SummaryThe Unfurl web app enables Flask debug mode even when configuration sets Details
PoC
PoC Script (inline)
ImpactIf the service is exposed beyond localhost (bound to 0.0.0.0 or reverse-proxied), an attacker can access the Werkzeug debugger. This can disclose sensitive information and may allow remote code execution if a debugger PIN is obtained. At minimum, stack traces and environment details are exposed on errors. Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
References Updated Jul 08, 2026 · Source: OSV.dev |
20221100
unknown
Dependencies (13)
+ 5 more |
|
20220200
unknown
2 CVEs
CVE-2026-40036
PYSEC-2026-1294
GHSA-h5qv-qjv4-pc5m
Jul 07, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
Network
Low
None
None
SummaryThe compressed data parser uses Details
PoC
PoC Script
ImpactA remote, unauthenticated attacker can cause high memory usage and potentially crash the service. The impact depends on deployment limits (process memory, URL length limits, and request size limits). Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
Fixed in
20260405
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-40035
GHSA-vg9h-jx4v-cwx2
Jan 29, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
Network
Low
None
None
SummaryThe Unfurl web app enables Flask debug mode even when configuration sets Details
PoC
PoC Script (inline)
ImpactIf the service is exposed beyond localhost (bound to 0.0.0.0 or reverse-proxied), an attacker can access the Werkzeug debugger. This can disclose sensitive information and may allow remote code execution if a debugger PIN is obtained. At minimum, stack traces and environment details are exposed on errors. Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
References Updated Jul 08, 2026 · Source: OSV.dev |
20220200
unknown
Dependencies (11)
+ 3 more |
|
20210615
unknown
2 CVEs
CVE-2026-40036
PYSEC-2026-1294
GHSA-h5qv-qjv4-pc5m
Jul 07, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
Network
Low
None
None
SummaryThe compressed data parser uses Details
PoC
PoC Script
ImpactA remote, unauthenticated attacker can cause high memory usage and potentially crash the service. The impact depends on deployment limits (process memory, URL length limits, and request size limits). Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
Fixed in
20260405
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-40035
GHSA-vg9h-jx4v-cwx2
Jan 29, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
Network
Low
None
None
SummaryThe Unfurl web app enables Flask debug mode even when configuration sets Details
PoC
PoC Script (inline)
ImpactIf the service is exposed beyond localhost (bound to 0.0.0.0 or reverse-proxied), an attacker can access the Werkzeug debugger. This can disclose sensitive information and may allow remote code execution if a debugger PIN is obtained. At minimum, stack traces and environment details are exposed on errors. Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
References Updated Jul 08, 2026 · Source: OSV.dev |
20210615
unknown
Dependencies (11)
+ 3 more |
|
20210311
unknown
2 CVEs
CVE-2026-40036
PYSEC-2026-1294
GHSA-h5qv-qjv4-pc5m
Jul 07, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
Network
Low
None
None
SummaryThe compressed data parser uses Details
PoC
PoC Script
ImpactA remote, unauthenticated attacker can cause high memory usage and potentially crash the service. The impact depends on deployment limits (process memory, URL length limits, and request size limits). Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
Fixed in
20260405
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-40035
GHSA-vg9h-jx4v-cwx2
Jan 29, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
Network
Low
None
None
SummaryThe Unfurl web app enables Flask debug mode even when configuration sets Details
PoC
PoC Script (inline)
ImpactIf the service is exposed beyond localhost (bound to 0.0.0.0 or reverse-proxied), an attacker can access the Werkzeug debugger. This can disclose sensitive information and may allow remote code execution if a debugger PIN is obtained. At minimum, stack traces and environment details are exposed on errors. Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
References Updated Jul 08, 2026 · Source: OSV.dev |
20210311
unknown
Dependencies (11)
+ 3 more |
|
20210310
unknown
2 CVEs
CVE-2026-40036
PYSEC-2026-1294
GHSA-h5qv-qjv4-pc5m
Jul 07, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
Network
Low
None
None
SummaryThe compressed data parser uses Details
PoC
PoC Script
ImpactA remote, unauthenticated attacker can cause high memory usage and potentially crash the service. The impact depends on deployment limits (process memory, URL length limits, and request size limits). Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
Fixed in
20260405
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-40035
GHSA-vg9h-jx4v-cwx2
Jan 29, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
Network
Low
None
None
SummaryThe Unfurl web app enables Flask debug mode even when configuration sets Details
PoC
PoC Script (inline)
ImpactIf the service is exposed beyond localhost (bound to 0.0.0.0 or reverse-proxied), an attacker can access the Werkzeug debugger. This can disclose sensitive information and may allow remote code execution if a debugger PIN is obtained. At minimum, stack traces and environment details are exposed on errors. Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
References Updated Jul 08, 2026 · Source: OSV.dev |
20210310
unknown
Dependencies (11)
+ 3 more |
|
20210309
unknown
2 CVEs
CVE-2026-40036
PYSEC-2026-1294
GHSA-h5qv-qjv4-pc5m
Jul 07, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
Network
Low
None
None
SummaryThe compressed data parser uses Details
PoC
PoC Script
ImpactA remote, unauthenticated attacker can cause high memory usage and potentially crash the service. The impact depends on deployment limits (process memory, URL length limits, and request size limits). Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
Fixed in
20260405
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-40035
GHSA-vg9h-jx4v-cwx2
Jan 29, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
Network
Low
None
None
SummaryThe Unfurl web app enables Flask debug mode even when configuration sets Details
PoC
PoC Script (inline)
ImpactIf the service is exposed beyond localhost (bound to 0.0.0.0 or reverse-proxied), an attacker can access the Werkzeug debugger. This can disclose sensitive information and may allow remote code execution if a debugger PIN is obtained. At minimum, stack traces and environment details are exposed on errors. Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
References Updated Jul 08, 2026 · Source: OSV.dev |
20210309
unknown
Dependencies (11)
+ 3 more |
|
20210308
unknown
2 CVEs
CVE-2026-40036
PYSEC-2026-1294
GHSA-h5qv-qjv4-pc5m
Jul 07, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
Network
Low
None
None
SummaryThe compressed data parser uses Details
PoC
PoC Script
ImpactA remote, unauthenticated attacker can cause high memory usage and potentially crash the service. The impact depends on deployment limits (process memory, URL length limits, and request size limits). Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
Fixed in
20260405
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-40035
GHSA-vg9h-jx4v-cwx2
Jan 29, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
Network
Low
None
None
SummaryThe Unfurl web app enables Flask debug mode even when configuration sets Details
PoC
PoC Script (inline)
ImpactIf the service is exposed beyond localhost (bound to 0.0.0.0 or reverse-proxied), an attacker can access the Werkzeug debugger. This can disclose sensitive information and may allow remote code execution if a debugger PIN is obtained. At minimum, stack traces and environment details are exposed on errors. Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
References Updated Jul 08, 2026 · Source: OSV.dev |
20210308
unknown
Dependencies (10)
+ 2 more |
|
20201102
unknown
2 CVEs
CVE-2026-40036
PYSEC-2026-1294
GHSA-h5qv-qjv4-pc5m
Jul 07, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
Network
Low
None
None
SummaryThe compressed data parser uses Details
PoC
PoC Script
ImpactA remote, unauthenticated attacker can cause high memory usage and potentially crash the service. The impact depends on deployment limits (process memory, URL length limits, and request size limits). Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
Fixed in
20260405
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-40035
GHSA-vg9h-jx4v-cwx2
Jan 29, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
Network
Low
None
None
SummaryThe Unfurl web app enables Flask debug mode even when configuration sets Details
PoC
PoC Script (inline)
ImpactIf the service is exposed beyond localhost (bound to 0.0.0.0 or reverse-proxied), an attacker can access the Werkzeug debugger. This can disclose sensitive information and may allow remote code execution if a debugger PIN is obtained. At minimum, stack traces and environment details are exposed on errors. Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
References Updated Jul 08, 2026 · Source: OSV.dev |
20201102
unknown
Dependencies (10)
+ 2 more |
|
20200812
unknown
2 CVEs
CVE-2026-40036
PYSEC-2026-1294
GHSA-h5qv-qjv4-pc5m
Jul 07, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
Network
Low
None
None
SummaryThe compressed data parser uses Details
PoC
PoC Script
ImpactA remote, unauthenticated attacker can cause high memory usage and potentially crash the service. The impact depends on deployment limits (process memory, URL length limits, and request size limits). Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
Fixed in
20260405
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-40035
GHSA-vg9h-jx4v-cwx2
Jan 29, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
Network
Low
None
None
SummaryThe Unfurl web app enables Flask debug mode even when configuration sets Details
PoC
PoC Script (inline)
ImpactIf the service is exposed beyond localhost (bound to 0.0.0.0 or reverse-proxied), an attacker can access the Werkzeug debugger. This can disclose sensitive information and may allow remote code execution if a debugger PIN is obtained. At minimum, stack traces and environment details are exposed on errors. Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
References Updated Jul 08, 2026 · Source: OSV.dev |
20200812
unknown
Dependencies (10)
+ 2 more |
|
20200729
unknown
2 CVEs
CVE-2026-40036
PYSEC-2026-1294
GHSA-h5qv-qjv4-pc5m
Jul 07, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
Network
Low
None
None
SummaryThe compressed data parser uses Details
PoC
PoC Script
ImpactA remote, unauthenticated attacker can cause high memory usage and potentially crash the service. The impact depends on deployment limits (process memory, URL length limits, and request size limits). Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
Fixed in
20260405
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-40035
GHSA-vg9h-jx4v-cwx2
Jan 29, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
Network
Low
None
None
SummaryThe Unfurl web app enables Flask debug mode even when configuration sets Details
PoC
PoC Script (inline)
ImpactIf the service is exposed beyond localhost (bound to 0.0.0.0 or reverse-proxied), an attacker can access the Werkzeug debugger. This can disclose sensitive information and may allow remote code execution if a debugger PIN is obtained. At minimum, stack traces and environment details are exposed on errors. Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
References Updated Jul 08, 2026 · Source: OSV.dev |
20200729
unknown
Dependencies (10)
+ 2 more |
|
20200703
unknown
2 CVEs
CVE-2026-40036
PYSEC-2026-1294
GHSA-h5qv-qjv4-pc5m
Jul 07, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
Network
Low
None
None
SummaryThe compressed data parser uses Details
PoC
PoC Script
ImpactA remote, unauthenticated attacker can cause high memory usage and potentially crash the service. The impact depends on deployment limits (process memory, URL length limits, and request size limits). Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
Fixed in
20260405
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-40035
GHSA-vg9h-jx4v-cwx2
Jan 29, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
Network
Low
None
None
SummaryThe Unfurl web app enables Flask debug mode even when configuration sets Details
PoC
PoC Script (inline)
ImpactIf the service is exposed beyond localhost (bound to 0.0.0.0 or reverse-proxied), an attacker can access the Werkzeug debugger. This can disclose sensitive information and may allow remote code execution if a debugger PIN is obtained. At minimum, stack traces and environment details are exposed on errors. Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
References Updated Jul 08, 2026 · Source: OSV.dev |
20200703
unknown
Dependencies (9)
+ 1 more |
|
20200702
unknown
2 CVEs
CVE-2026-40036
PYSEC-2026-1294
GHSA-h5qv-qjv4-pc5m
Jul 07, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
Network
Low
None
None
SummaryThe compressed data parser uses Details
PoC
PoC Script
ImpactA remote, unauthenticated attacker can cause high memory usage and potentially crash the service. The impact depends on deployment limits (process memory, URL length limits, and request size limits). Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
Fixed in
20260405
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-40035
GHSA-vg9h-jx4v-cwx2
Jan 29, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
Network
Low
None
None
SummaryThe Unfurl web app enables Flask debug mode even when configuration sets Details
PoC
PoC Script (inline)
ImpactIf the service is exposed beyond localhost (bound to 0.0.0.0 or reverse-proxied), an attacker can access the Werkzeug debugger. This can disclose sensitive information and may allow remote code execution if a debugger PIN is obtained. At minimum, stack traces and environment details are exposed on errors. Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
References Updated Jul 08, 2026 · Source: OSV.dev |
20200702
unknown
Dependencies (9)
+ 1 more |
|
20200630.4
minor
2 CVEs
CVE-2026-40036
PYSEC-2026-1294
GHSA-h5qv-qjv4-pc5m
Jul 07, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
Network
Low
None
None
SummaryThe compressed data parser uses Details
PoC
PoC Script
ImpactA remote, unauthenticated attacker can cause high memory usage and potentially crash the service. The impact depends on deployment limits (process memory, URL length limits, and request size limits). Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
Fixed in
20260405
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-40035
GHSA-vg9h-jx4v-cwx2
Jan 29, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
Network
Low
None
None
SummaryThe Unfurl web app enables Flask debug mode even when configuration sets Details
PoC
PoC Script (inline)
ImpactIf the service is exposed beyond localhost (bound to 0.0.0.0 or reverse-proxied), an attacker can access the Werkzeug debugger. This can disclose sensitive information and may allow remote code execution if a debugger PIN is obtained. At minimum, stack traces and environment details are exposed on errors. Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
References Updated Jul 08, 2026 · Source: OSV.dev |
20200630.4
minor
Dependencies (9)
+ 1 more |
|
20200630.3
minor
2 CVEs
CVE-2026-40036
PYSEC-2026-1294
GHSA-h5qv-qjv4-pc5m
Jul 07, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
Network
Low
None
None
SummaryThe compressed data parser uses Details
PoC
PoC Script
ImpactA remote, unauthenticated attacker can cause high memory usage and potentially crash the service. The impact depends on deployment limits (process memory, URL length limits, and request size limits). Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
Fixed in
20260405
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-40035
GHSA-vg9h-jx4v-cwx2
Jan 29, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
Network
Low
None
None
SummaryThe Unfurl web app enables Flask debug mode even when configuration sets Details
PoC
PoC Script (inline)
ImpactIf the service is exposed beyond localhost (bound to 0.0.0.0 or reverse-proxied), an attacker can access the Werkzeug debugger. This can disclose sensitive information and may allow remote code execution if a debugger PIN is obtained. At minimum, stack traces and environment details are exposed on errors. Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
References Updated Jul 08, 2026 · Source: OSV.dev |
20200630.3
minor
Dependencies (9)
+ 1 more |
|
20200630.2
initial
2 CVEs
CVE-2026-40036
PYSEC-2026-1294
GHSA-h5qv-qjv4-pc5m
Jul 07, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
Network
Low
None
None
SummaryThe compressed data parser uses Details
PoC
PoC Script
ImpactA remote, unauthenticated attacker can cause high memory usage and potentially crash the service. The impact depends on deployment limits (process memory, URL length limits, and request size limits). Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
Fixed in
20260405
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-40035
GHSA-vg9h-jx4v-cwx2
Jan 29, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
Network
Low
None
None
SummaryThe Unfurl web app enables Flask debug mode even when configuration sets Details
PoC
PoC Script (inline)
ImpactIf the service is exposed beyond localhost (bound to 0.0.0.0 or reverse-proxied), an attacker can access the Werkzeug debugger. This can disclose sensitive information and may allow remote code execution if a debugger PIN is obtained. At minimum, stack traces and environment details are exposed on errors. Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
References Updated Jul 08, 2026 · Source: OSV.dev |
20200630.2
initial
Dependencies (9)
+ 1 more |
|
20200630
unknown
2 CVEs
CVE-2026-40036
PYSEC-2026-1294
GHSA-h5qv-qjv4-pc5m
Jul 07, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
Network
Low
None
None
SummaryThe compressed data parser uses Details
PoC
PoC Script
ImpactA remote, unauthenticated attacker can cause high memory usage and potentially crash the service. The impact depends on deployment limits (process memory, URL length limits, and request size limits). Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
Fixed in
20260405
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-40035
GHSA-vg9h-jx4v-cwx2
Jan 29, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
Network
Low
None
None
SummaryThe Unfurl web app enables Flask debug mode even when configuration sets Details
PoC
PoC Script (inline)
ImpactIf the service is exposed beyond localhost (bound to 0.0.0.0 or reverse-proxied), an attacker can access the Werkzeug debugger. This can disclose sensitive information and may allow remote code execution if a debugger PIN is obtained. At minimum, stack traces and environment details are exposed on errors. Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
References Updated Jul 08, 2026 · Source: OSV.dev |
20200630
unknown
Dependencies (9)
+ 1 more |
|
20200629
unknown
2 CVEs
CVE-2026-40036
PYSEC-2026-1294
GHSA-h5qv-qjv4-pc5m
Jul 07, 2026
Unfurl's unbounded zlib decompression allows decompression bomb DoS
High
Network
Low
None
None
SummaryThe compressed data parser uses Details
PoC
PoC Script
ImpactA remote, unauthenticated attacker can cause high memory usage and potentially crash the service. The impact depends on deployment limits (process memory, URL length limits, and request size limits). Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
Fixed in
20260405
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-40035
GHSA-vg9h-jx4v-cwx2
Jan 29, 2026
Unfurl's debug mode cannot be disabled due to string config parsing (Werkzeug debugger exposure)
Critical
Network
Low
None
None
SummaryThe Unfurl web app enables Flask debug mode even when configuration sets Details
PoC
PoC Script (inline)
ImpactIf the service is exposed beyond localhost (bound to 0.0.0.0 or reverse-proxied), an attacker can access the Werkzeug debugger. This can disclose sensitive information and may allow remote code execution if a debugger PIN is obtained. At minimum, stack traces and environment details are exposed on errors. Affected versions
20200629
20200630
20200630.2
20200630.3
20200630.4
20200702
20200703
20200729
20200812
20201102
20210308
20210309
+ 15 more Show less
20210310
20210311
20210615
20220200
20221100
20230900
20230901
20240625
20240626
20240627
20241120
20241121
20250218
20250312
20250810
References Updated Jul 08, 2026 · Source: OSV.dev |
20200629
unknown
Dependencies (9)
+ 1 more |