RubySec

Providing security resources for the Ruby community

GHSA-3553-vcg5-72jw (dalli): Unbounded decompression and reply sizes allow memory exhaustion

Unbounded decompression and reply sizes allow memory exhaustion

Published: October 05, 2026

SECURITY IDENTIFIERS

GEM

dalli

PATCHED VERSIONS

~> 3.2.12 ~> 4.3.6 ~> 5.0.9 ~> 5.1.3 >= 5.2.1

DESCRIPTION

  1. Values flagged as compressed were inflated with no size limit. A ~130 KB stored item expands to 128 MB on read (about 1000:1), regardless of the client's compress or serializer settings.
  2. The size in a reply (a meta VA <size>, or a binary body length) was used to read or buffer that many bytes, so a hostile or compromised server could make the client allocate gigabytes.

Exploiting either requires write access to the memcached instance (a shared or exposed instance, another tenant), or a malicious server or proxy. Patched versions add a decompressed_max_bytes option (default 128 MiB) and reject reply sizes over 1 GiB.

RELATED