CVE-2024-3508 - CVE House
Back to Database
Status published Medium CVE-2024-3508

Bzip2: compressed content bomb leads to denial of service of bombastic api

Vulnerability Description

A flaw was found in Bombastic, which allows authenticated users to upload compressed (bzip2 or zstd) SBOMs. The API endpoint verifies the presence of some fields and values in the JSON. To perform this verification, the uploaded file must first be decompressed.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-3508

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Red Hat Trusted Profile Analyzer
Vulnerable Versions:
faa7a496c5d98e0f0859dd2c623eddf82289eaa8

Timeline

Official Publish: April 25th, 2024
Last Modified: November 20th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Weaknesses (CWE)