Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
elixir-tesla tesla — Decompression bomb in Tesla.Middleware.DecompressResponse and Tesla.Middleware.Compression
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L P N N N N H 8.2 .0046 37.9 —
AFFECTED
Product Versions Fixed
tesla 0.6.0 – —
tesla 5bd90bb5cf0d15e375edc2a66fa322292940fce2 – —
TIMELINE
May 22 Reserved by EEF
Jun 2 EXPLOIT PUBLISHED — CVE-2026-48594 (elixir-tesla tesla). Public exploit reference added.
Jun 2 Published (CNA: EEF)
Description
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-tesla tesla allows a denial of service via decompression bomb in HTTP response bodies.
When Tesla.Middleware.DecompressResponse or Tesla.Middleware.Compression is included in a Tesla middleware pipeline, HTTP response bodies are decompressed eagerly with no size limit. The decompress_body/2 function in lib/tesla/middleware/compression.ex passes the entire response body to :zlib.gunzip/1 or :zlib.unzip/1 without any cap on the output size. Additionally, compression_algorithms/1 splits the content-encoding header on commas and decompress_body/2 recurses once per token, applying a decompression pass on each iteration. A server advertising content-encoding: gzip, gzip, gzip, gzip causes four recursive decompression passes, yielding exponential amplification: each gzip layer can expand its input roughly 1000x, so a payload of a few hundred bytes on the wire inflates to gigabytes of BEAM heap, exhausting memory and crashing or freezing the calling process.
This issue affects tesla: from 0.6.0 before 1.18.3.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| May 22, 2026 | Reserved | Reserved by EEF |
| June 2, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-48594 (elixir-tesla tesla). Public exploit reference added. |
| June 2, 2026 | Published | Published (CNA: EEF) |
Affected
Affected products and packages — 2 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| elixir-tesla | tesla | — | 0.6.0 | — |
| elixir-tesla | tesla | — | 5bd90bb5cf0d15e375edc2a66fa322292940fce2 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-48594 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.