<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cve-2026-28318 on Aretiq AI</title><link>https://aretiq.ai/tags/cve-2026-28318/</link><description>Recent content in Cve-2026-28318 on Aretiq AI</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 07 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://aretiq.ai/tags/cve-2026-28318/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-28318 — SolarWinds Serv-U HTTP Deflate Uncontrolled Resource Consumption</title><link>https://aretiq.ai/research/vul260607-cve-2026-28318-solarwinds-serv-u-http-deflate-uncontrolled-resource-consumption/</link><pubDate>Sun, 07 Jun 2026 00:00:00 +0000</pubDate><guid>https://aretiq.ai/research/vul260607-cve-2026-28318-solarwinds-serv-u-http-deflate-uncontrolled-resource-consumption/</guid><description>&lt;h2 id="1-overview">1. Overview&lt;/h2>
&lt;p>A vulnerability exists in SolarWinds Serv-U&amp;rsquo;s HTTP request handler that processes &lt;code>Content-Encoding: deflate&lt;/code> encoded POST bodies. The server decompresses incoming deflate-encoded payloads without enforcing any limit on the decompressed size, allowing an attacker to send a small (~260KB) compressed payload that expands to hundreds of megabytes or gigabytes in memory. This uncontrolled memory allocation causes the Serv-U process to crash with SIGABRT, resulting in a complete denial of service. The attack requires no authentication and can be performed by any network-accessible client. SolarWinds addressed this vulnerability in Serv-U 15.5.4 Hotfix 1, released June 4, 2026. CISA added this CVE to the Known Exploited Vulnerabilities catalog on June 5, 2026, citing active exploitation in the wild.&lt;/p></description></item></channel></rss>