CVE-2019-25072: Tendermint

High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.

Due to support of Gzip compression in request bodies, as well as a lack of limiting response body sizes, a malicious server can cause a client to consume a significant amount of system resources, which may be used as a denial of service vector.

Affected products

  • Tendermint Tendermint: before 0.31.1 (fixed in 0.31.1)

Published 2022-12-27. Last modified 2026-06-17.