CVE-2022-2883: Octopus Server

High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.

In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service

Affected products

  • Octopus Octopus Server: before 2022.3.11043 (fixed in 2022.3.11043); from 2022.4.0, before 2022.4.8401 (fixed in 2022.4.8401)

Published 2023-02-22. Last modified 2026-06-17.