PT-2026-65909 · Olivetin · Olivetin

CVE-2026-67437

·

Published

2026-07-29

·

Updated

2026-09-04

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OliveTin versions 3000.0.0 through 3000.16.0
Description The OAuth2 login handler in service/internal/auth/otoauth2/restapi auth oauth2.go stores per-login state in the registeredStates map for every request made to the /oauth/login endpoint. Because these entries are not expired, deleted, or bounded, an unauthenticated attacker can exhaust system memory, leading to a denial of service.
Recommendations Update to version 3000.17.0.

Exploit

Fix

Resource Exhaustion

Allocation of Resources Without Limits

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67437
GHSA-XPXJ-F2FM-RQCH
GO-2026-6146
OPENSUSE-SU-2026:21761-1

Affected Products

Olivetin