PT-2026-79420 · Checkmate · Checkmate

CVE-2026-55241

·

Published

2026-08-21

·

Updated

2026-08-25

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Checkmate versions prior to 3.9.1
Description An unauthenticated attacker can cause a denial of service by submitting concurrent oversized files to the 'POST /api/v1/auth/register' endpoint. The application uses in-memory Multer parsing for the profileImage variable before performing registration or invite-token validation. Because there are no limits on file size, file count, or MIME-type, these files are buffered in memory, which can exhaust system resources and crash or destabilize the backend.
Recommendations Update to version 3.9.1.

Exploit

Fix

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55241
GHSA-9XVG-X28F-M78M

Affected Products

Checkmate