Mesop · Mesop · CVE-2026-77357
**Name of the Vulnerable Software and Affected Versions**
Mesop versions prior to 1.3.3
**Description**
Applications running in debug mode expose a GET '/hot-reload' endpoint. An unauthenticated attacker can provide high values to the `counter` parameter, triggering an unbounded loop that holds worker threads. This leads to worker pool exhaustion, causing the server to become unresponsive and crash, requiring a manual restart to restore service.
**Recommendations**
Update to version 1.3.3.