The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.
{ "cwe_ids": [] }
"https://github.com/psf/advisory-database/blob/main/advisories/python/PSF-2020-1.json"