CVE-2026-53781 Details
Description
Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers to cause disk exhaustion by serving media responses that bypass the enforced size limit through missing or misreported Content-Length headers, chunked transfer encoding, or failed HEAD requests. Attackers who control a podcast feed or media URL can stream an unbounded response to local storage via the temp-file download path, exhausting disk or system resources on the host running the CLI.
A resource exhaustion vulnerability has been identified in Steipete Summarize versions prior to 0.17.0. This vulnerability allows remote attackers to cause disk exhaustion by sending media responses that bypass the enforced size limit. Exploitation can occur through missing or misreported Content-Length headers, chunked transfer encoding, or failed HEAD requests. Attackers controlling a podcast feed or media URL can stream an unbounded response to local storage via the temporary file download path, exhausting disk or system resources on the host running the command-line interface (CLI).
Users can update to Steipete Summarize version 0.17.1 or later, where this vulnerability has been addressed. Instructions for downloading the latest version are available on the Steipete Summarize GitHub releases page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 11, 2026CISA-ADP
Assessed Jun 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/steipete/summarize/commit/14de194c24c5e0fba4bdb4a6f7766eb6ea3ed750 | [email protected] | Source CodeVendor |
| https://github.com/steipete/summarize/pull/237 | [email protected] | Issue TrackingVendor |
| https://github.com/steipete/summarize/releases/tag/v0.17.0 | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/summarize-disk-exhaustion-via-uncapped-media-download | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Summarize | < 0.17.0 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 11, 2026 | New CVE Received | [email protected] |
Volerion