Description
Avro Decompression Bomb PoC CWE-409 Proof of concept demonstrating a decompression bomb vulnerability in Apache Avro's Java codec layer. A crafted Avro file that is 50 KB on disk decompresses to 50 MB at read time, causing java.lang.OutOfMemoryError...
Basic Information
ID
1F90FE83-50A3-56CF-B4AF-B7A9527E8817
Published
May 6, 2026 at 14:59