Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gfvj-j222-m85v

Опубликовано: 20 мая 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.1
CVSS3: 7.5

Описание

The CSP report endpoint intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and contribute to resource exhaustion or log flooding.

The CSP report endpoint intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and contribute to resource exhaustion or log flooding.

EPSS

Процентиль: 28%
0.00365
Низкий

5.1 Medium

CVSS4

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
nvd
2 месяца назад

The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and contribute to resource exhaustion or log flooding.

EPSS

Процентиль: 28%
0.00365
Низкий

5.1 Medium

CVSS4

7.5 High

CVSS3

Дефекты

CWE-400