Impact
Yopass exposes a metrics middleware that uses the HTTP method from incoming requests as a Prometheus metric label. Because the route accepts arbitrary method strings, an attacker can send many unique method values, causing the Prometheus registry to create an unlimited number of metric series. This unbounded growth consumes increasing amounts of memory and can eventually trigger an out‑of‑memory kill, leading to a denial of service. The continuous addition of series also degrades scrape latency from the metrics endpoint and can mask the health of the service by hiding actual workload metrics.
Affected Systems
The vulnerability affects the Yopass secret‑sharing service produced by jhaals. All released versions before 14.7.0 are impacted. The issue is fixed in release 14.7.0 and later.
Risk and Exploitability
An unauthenticated external attacker able to craft HTTP requests can exploit this flaw by specifying a large number of distinct method names. The exploitation requires no authentication and can be performed over any open network endpoint exposed by Yopass. The CVSS score of 7.5 indicates a high severity and the lack of an EPSS score means there is no current evidence of exploitation in the wild, but the attack vector is straightforward and could be automated. Because the flaw leads to memory exhaustion and service termination, it constitutes a denial‑of‑service risk. vulnerability is not listed in CISA’s KEV catalog, implying it has not yet been observed as a widely used exploitation.
OpenCVE Enrichment