PT-2026-55916 · Wso2 · Wso2 Universal Gateway+3
CVE-2026-4249
·
Published
2026-07-06
·
Updated
2026-07-06
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
WSO2 API Manager versions 3.2.0 through 4.7.0
WSO2 Universal Gateway (affected versions not specified)
WSO2 Traffic Manager (affected versions not specified)
WSO2 API Control Plane (affected versions not specified)
Description
The throttling event handling mechanism accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an unauthenticated remote attacker to inject malicious JSON data, causing the API Gateway to crash. This results in a persistent denial of service (DoS) condition, where legitimate API traffic is blocked and all services behind the gateway are unavailable. Recovery from this state requires manual intervention.
Recommendations
Update WSO2 API Manager to the fixed patch levels specified in advisory WSO2-2026-5236.
Update WSO2 Universal Gateway to the fixed patch levels specified in advisory WSO2-2026-5236.
Update WSO2 Traffic Manager to the fixed patch levels specified in advisory WSO2-2026-5236.
Update WSO2 API Control Plane to the fixed patch levels specified in advisory WSO2-2026-5236.
Fix
DoS
Improper Neutralization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wso2 Api Control Plane
Wso2 Api Manager
Wso2 Traffic Manager
Wso2 Universal Gateway