PT-2026-109293 · Yopass · Yopass
CVE-2026-107840
·
Published
2026-10-09
·
Updated
2026-10-09
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
yopass versions prior to 14.7.0
Description
The Prometheus metrics middleware in
pkg/server/server.go uses the r.Method value directly as a label for the yopass http requests total and yopass http request duration seconds metrics. Because the catch-all route accepts arbitrary HTTP method tokens, an unauthenticated remote attacker can submit numerous unique methods. This creates metric series that the Prometheus registry never evicts, leading to monotonic memory growth that can result in an Out-Of-Memory (OOM) kill of the process. Furthermore, the expanding registry increases scrape latency for the /metrics endpoint, which can cause timeouts and blind monitoring systems.Recommendations
Update to version 14.7.0 or later.
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yopass