CVE-2023-3782: Squareup Okhttp-Brotli

Medium severity, CVSS 5.9. EPSS: 0.7% chance of exploitation in the next 30 days.

DoS of the OkHttp client when using a BrotliInterceptor and surfing to a malicious web server, or when an attacker can perform MitM to inject a Brotli zip-bomb into an HTTP response

Affected products

Published 2023-07-19. Last modified 2026-06-17.