boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-48594HIGH
elixir-tesla tesla — Decompression bomb in Tesla.Middleware.DecompressResponse and Tesla.Middleware.Compression
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   P   N   N   N   N   H    8.2   .0046   37.9     —
AFFECTED
  Product  Versions                                    Fixed
  tesla    0.6.0 –                                     —
  tesla    5bd90bb5cf0d15e375edc2a66fa322292940fce2 –  —
TIMELINE
  May 22  Reserved by EEF
  Jun 2   EXPLOIT PUBLISHED — CVE-2026-48594 (elixir-tesla tesla). Public exploit reference added.
  Jun 2   Published (CNA: EEF)
CWE-409 · CNA: EEF · CVSS v4.0 · 4 references · NVD status: Analyzed

Description

Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-tesla tesla allows a denial of service via decompression bomb in HTTP response bodies. When Tesla.Middleware.DecompressResponse or Tesla.Middleware.Compression is included in a Tesla middleware pipeline, HTTP response bodies are decompressed eagerly with no size limit. The decompress_body/2 function in lib/tesla/middleware/compression.ex passes the entire response body to :zlib.gunzip/1 or :zlib.unzip/1 without any cap on the output size. Additionally, compression_algorithms/1 splits the content-encoding header on commas and decompress_body/2 recurses once per token, applying a decompression pass on each iteration. A server advertising content-encoding: gzip, gzip, gzip, gzip causes four recursive decompression passes, yielding exponential amplification: each gzip layer can expand its input roughly 1000x, so a payload of a few hundred bytes on the wire inflates to gigabytes of BEAM heap, exhausting memory and crashing or freezing the calling process. This issue affects tesla: from 0.6.0 before 1.18.3.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
May 22, 2026ReservedReserved by EEF
June 2, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-48594 (elixir-tesla tesla). Public exploit reference added.
June 2, 2026PublishedPublished (CNA: EEF)

Affected

Affected products and packages — 2 rows
VendorProduct / PackageEcosystemVersion introducedFixed
elixir-teslatesla0.6.0
elixir-teslatesla5bd90bb5cf0d15e375edc2a66fa322292940fce2

Weaknesses

CWE-409

References (4)

Related

Authoritative record: CVE-2026-48594 at cve.org

Vendors: elixir-tesla

Weaknesses: CWE-409

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-48594 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.