Feed/CVE-2026-67437
CVE-2026-67437HIGHCVSS 7.5

CVE-2026-67437

Published Jul 29, 2026·Updated Jul 30, 2026

NVD Description

OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_auth_oauth2.go OAuth2 login handler stores per-login state in the registeredStates map on every /oauth/login request without expiring, deleting, or bounding entries, allowing an unauthenticated attacker to exhaust memory and cause a denial of service. This issue is fixed in version 3000.17.0.

Affected Packages (1)

github.com/OliveTin/OliveTinGO
From 0.0.0-20251024001301-45f9c18bc3ee
Fixed in 0.0.0-20260708075951-ec114e95d297

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free