Description
Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to render a Pexip Infinity node inaccessible.
Published: 2026-09-30
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: Denial of Service (remote availability impact)
Action: Update Software
AI Analysis

Impact

Pexip Infinity versions 30.0 through 40.x before 41.0 suffer from improper input validation in the web server, permitting a malicious actor to send crafted requests that render a node inaccessible. The failure of the web server to correctly sanitize input causes a denial‑of‑service condition that interrupts service availability for users and communications relying on that node. The presence of CWE‑770 indicates an out‑of‑memory or resource exhaustion weakness exploited by the attacker to exhaust or corrupt server resources.

Affected Systems

The affected products are Pexip Infinity, specifically all releases from version 30.0 up through any 40.x build prior to 41.0. Users deploying these versions should verify their build number and plan for remediation.

Risk and Exploitability

The CVSS score of 8.6 classifies this as a high‑severity vulnerability. The EPSS score is not available, and it is not listed in the CISA KEV catalog, suggesting that while the flaw is serious, it may not yet have widespread exploitation reports. The vulnerability is likely mountable remotely by targeting the Infinity web interface; an attacker must be able to reach the web server over the network and craft the invalid input to trigger the denial of service. Given the absence of additional constraints in the description, the attack vector is inferred to be remote and network‑based.

Generated by OpenCVE AI on September 30, 2026 at 06:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Pexip Infinity to version 41.0 or later, which contains the fix for the input validation flaw.
  • If an upgrade is not immediately possible, limit external access to the Infinity web interface by restricting traffic to trusted IP ranges or applying firewall rules that filter out malformed requests.
  • Enable detailed logging and monitor for repeated anomalous requests to the web server, and consider applying rate‑limiting or request validation rules at the application gateway to mitigate accidental denial of service.

Generated by OpenCVE AI on September 30, 2026 at 06:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Title Pexip Infinity Denial of Service via Improper Input Validation

Wed, 30 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to render a Pexip Infinity node inaccessible.
First Time appeared Pexip
Pexip infinity
Weaknesses CWE-770
CPEs cpe:2.3:a:pexip:infinity:*:*:*:*:*:*:*:*
Vendors & Products Pexip
Pexip infinity
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-30T02:24:28.821Z

Reserved: 2026-09-30T02:24:27.936Z

Link: CVE-2026-103101

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T03:16:59.033

Modified: 2026-09-30T03:16:59.033

Link: CVE-2026-103101

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T06:45:13Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling