{"id":"CVE-2026-53781","aliases":["GHSA-q9xm-f36c-xm3q"],"url":"https://o3.security/vulnerability/CVE-2026-53781","summary":"Summarize < 0.17.0 Disk Exhaustion via Uncapped Media Download","details":"Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers to cause disk exhaustion by serving media responses that bypass the enforced size limit through missing or misreported Content-Length headers, chunked transfer encoding, or failed HEAD requests. Attackers who control a podcast feed or media URL can stream an unbounded response to local storage via the temp-file download path, exhausting disk or system resources on the host running the CLI.","published":"2026-06-11T19:11:49.211Z","modified":"2026-08-12T03:51:44.700342200Z","cvss":null,"epss":{"score":0.00324,"percentile":0.24702,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@steipete/summarize-core","fixedVersion":"0.17.0"}],"fix":{"url":"https://github.com/steipete/summarize/commit/14de194c24c5e0fba4bdb4a6f7766eb6ea3ed750","label":"steipete/summarize@14de194"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53781.json"},{"type":"ADVISORY","url":"https://github.com/steipete/summarize/releases/tag/v0.17.0"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53781"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/summarize-disk-exhaustion-via-uncapped-media-download"},{"type":"REPORT","url":"https://github.com/steipete/summarize/pull/237"},{"type":"FIX","url":"https://github.com/steipete/summarize/commit/14de194c24c5e0fba4bdb4a6f7766eb6ea3ed750"},{"type":"PACKAGE","url":"https://github.com/steipete/summarize"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:44.700342200Z"}}