PT-2026-65909 · Olivetin · Olivetin
CVE-2026-67437
·
Published
2026-07-29
·
Updated
2026-09-04
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OliveTin versions 3000.0.0 through 3000.16.0
Description
The OAuth2 login handler in
service/internal/auth/otoauth2/restapi auth oauth2.go stores per-login state in the registeredStates map for every request made to the /oauth/login endpoint. Because these entries are not expired, deleted, or bounded, an unauthenticated attacker can exhaust system memory, leading to a denial of service.Recommendations
Update to version 3000.17.0.
Exploit
Fix
Resource Exhaustion
Allocation of Resources Without Limits
Memory Leak
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Olivetin