CVE-2019-25072: Tendermint Client package vulnerable to Uncontrolled Resource Consumption
(updated )
Due to support of Gzip compression in request bodies, as well as a lack of limiting response body sizes, a malicious server can cause a client to consume a significant amount of system resources, which may be used as a denial of service vector.
References
Detect and mitigate CVE-2019-25072 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →