Unbounded decompression and reply sizes allow memory exhaustion
Published: October 05, 2026
SECURITY IDENTIFIERS
- GHSA: GHSA-3553-vcg5-72jw
- Vendor Advisory: https://github.com/petergoldstein/dalli/security/advisories/GHSA-3553-vcg5-72jw
GEM
PATCHED VERSIONS
~> 3.2.12
~> 4.3.6
~> 5.0.9
~> 5.1.3
>= 5.2.1
DESCRIPTION
- Values flagged as compressed were inflated with no size limit. A
~130 KB stored item expands to 128 MB on read (about 1000:1),
regardless of the client's
compressorserializersettings. - The size in a reply (a meta
VA <size>, or a binary body length) was used to read or buffer that many bytes, so a hostile or compromised server could make the client allocate gigabytes.
Exploiting either requires write access to the memcached instance (a
shared or exposed instance, another tenant), or a malicious server or
proxy. Patched versions add a decompressed_max_bytes option (default
128 MiB) and reject reply sizes over 1 GiB.
RELATED
- https://github.com/petergoldstein/dalli/security/advisories/GHSA-3553-vcg5-72jw
- https://github.com/petergoldstein/dalli/commit/39d2f72
- https://rubygems.org/gems/dalli/versions/5.2.1
- https://github.com/petergoldstein/dalli/releases/tag/v5.2.1
- https://rubygems.org/gems/dalli/versions/5.1.3
- https://github.com/petergoldstein/dalli/releases/tag/v5.1.3
- https://rubygems.org/gems/dalli/versions/5.0.9
- https://github.com/petergoldstein/dalli/releases/tag/v5.0.9
- https://rubygems.org/gems/dalli/versions/4.3.6
- https://github.com/petergoldstein/dalli/releases/tag/v4.3.6
- https://rubygems.org/gems/dalli/versions/3.2.12
- https://github.com/petergoldstein/dalli/releases/tag/v3.2.12
