Tag

#Denial of Service

newsHIGH 8.2

Next.js Denial of Service Vulnerability in App Router using Server Actions

A denial of service vulnerability exists in Next.js applications using App Router with at least one Server Action. Crafted requests can lead to excessive CPU usage, blocking further requests. Affected versions include Next.js 13.0.0 to 15.5.20 and 16.0.0 to 16.2.10.

1 source
blogHIGH 7.4

Understanding and Defending Against CVE-2026-10665: Remote Memory Corruption in Zephyr's WireGuard Subsystem

CVE-2026-10665 is a high-severity vulnerability in Zephyr's WireGuard subsystem that allows for remote memory corruption and denial of service. The vulnerability is caused by an out-of-bounds write in the wg_process_data_message() function. This educational analysis will provide an in-depth look at the vulnerability, its exploitation mechanics, and defensive strategies.

1 source
articleHIGH 7.8

Critical Use-After-Free Vulnerability in Zephyr's Dynamic Kernel-Object Tracking (CVE-2026-10667)

A critical use-after-free vulnerability (CVE-2026-10667) has been discovered in Zephyr's dynamic kernel-object tracking, affecting SMP systems with userspace enabled. This vulnerability allows a deprivileged user thread to corrupt kernel object-tracking structures, potentially leading to privilege escalation or denial of service. The vulnerability has a CVSS score of 7.8 and affects Zephyr versions from 1.14.0 to 4.4.0. Immediate patching is recommended to prevent potential exploitation.

1 source
blogHIGH 8.2

Understanding and Defending Against Tesla's Atom Exhaustion Vulnerability via Untrusted URL Scheme

This educational analysis delves into a critical vulnerability in the Tesla HTTP client library, specifically in the Mint adapter, which allows for remote denial of service through atom exhaustion. The vulnerability, tracked as CVE-2026-48597, has a CVSS score of 8.2 and affects Tesla versions 1.3.0 through 1.18.2. We will explore the root cause, attack surface, exploitation mechanics, real-world impact, and provide defensive strategies.

1 source
newsHIGH 8.7

Mistune Vulnerability: Potential DoS via Quadratic-Time Parsing in parse_link_text

Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (approximately O(n²)) behavior in parse_link_text. An attacker-controlled Markdown input can trigger excessive CPU usage with a very small payload. Affected applications include web applications, API services, and documentation rendering systems.

1 source
newsMEDIUM 4.3

GitLab CVE-2026-10733 Vulnerability

GitLab has remediated a vulnerability in GitLab CE/EE that could allow an authenticated user to cause a denial of service on the CI/CD Catalog page.

1 source