CVE-2019-25072: Tendermint
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
Due to support of Gzip compression in request bodies, as well as a lack of limiting response body sizes, a malicious server can cause a client to consume a significant amount of system resources, which may be used as a denial of service vector.
Affected products
- Tendermint Tendermint: before 0.31.1 (fixed in 0.31.1)
Published 2022-12-27. Last modified 2026-06-17.