PT-2026-109293 · Yopass · Yopass

CVE-2026-107840

·

Published

2026-10-09

·

Updated

2026-10-09

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions yopass versions prior to 14.7.0
Description The Prometheus metrics middleware in pkg/server/server.go uses the r.Method value directly as a label for the yopass http requests total and yopass http request duration seconds metrics. Because the catch-all route accepts arbitrary HTTP method tokens, an unauthenticated remote attacker can submit numerous unique methods. This creates metric series that the Prometheus registry never evicts, leading to monotonic memory growth that can result in an Out-Of-Memory (OOM) kill of the process. Furthermore, the expanding registry increases scrape latency for the /metrics endpoint, which can cause timeouts and blind monitoring systems.
Recommendations Update to version 14.7.0 or later.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107840
GHSA-6R69-C6WG-7G8M

Affected Products

Yopass