CRIME is a compression side-channel vulnerability affecting TLS 1.2 and earlier when TLS-level compression is negotiated. Compression of request data containing both a secret HTTP header, such as an authentication cookie, and attacker-influenced plaintext causes ciphertext lengths to vary according to whether guessed input matches portions of the secret. An active man-in-the-middle can induce repeated requests and measure encrypted record lengths to iteratively recover header plaintext. The issue affected implementations including certain versions of Firefox, Chrome, Qt, OpenSSL-based products, and protocols using compressed request headers such as SPDY.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository provides a proof-of-concept (PoC) implementation of the CRIME attack (CVE-2012-4929), which exploits the use of data compression prior to encryption in TLS/SSL protocols. The repository contains two main Python scripts: 'CRIME-cbc-poc.py' and 'CRIME-rc4-poc.py'. Each script demonstrates the attack against a simulated environment using either AES-CBC or RC4 encryption, respectively. The attack works by adaptively crafting plaintexts and observing the length of the resulting compressed and encrypted data, allowing the attacker to recover secret information (such as cookies or tokens) byte by byte. The PoC is self-contained and does not target a real server, but rather simulates the vulnerable behavior locally. The README provides a detailed explanation of the attack, its theory, and how the PoC scripts implement the recursive 'two_tries' method to recover secrets. No network endpoints or real-world targets are hardcoded; the scripts are intended for educational and demonstration purposes only.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A TLS compression-related attack referenced in test output indicating the evaluated setup is not vulnerable.
A network-accessible Apache vulnerability addressed by HP-UX Web Server Suite v3.26; its listed CVSS v2 score is 2.6 and confidentiality impact is partial.
The CRIME attack is a TLS compression side-channel vulnerability affecting TLS 1.2 and earlier. A man-in-the-middle can infer plaintext HTTP-header values by observing ciphertext-length differences across crafted requests.
A compression side-channel vulnerability affecting HTTPS/SPDY/TLS/HTTP compression that can leak secret cookies and enable session hijacking.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.