Description
yopass is a service for securely sharing secrets, passwords, and files. Prior to version 14.7.0, the Prometheus metrics middleware in pkg/server/server.go uses the attacker-controlled r.Method value directly as the method label for yopass_http_requests_total and yopass_http_request_duration_seconds. Because the catch-all route accepts arbitrary HTTP method tokens, an unauthenticated remote attacker can submit many unique methods and create metric series that the Prometheus registry never evicts. The resulting monotonic memory growth can OOM-kill the process, while the expanding registry also degrades /metrics scrape latency and can blind monitoring. This issue is fixed in version 14.7.0.
Published: 2026-10-09
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

Yopass exposes a metrics middleware that uses the HTTP method from incoming requests as a Prometheus metric label. Because the route accepts arbitrary method strings, an attacker can send many unique method values, causing the Prometheus registry to create an unlimited number of metric series. This unbounded growth consumes increasing amounts of memory and can eventually trigger an out‑of‑memory kill, leading to a denial of service. The continuous addition of series also degrades scrape latency from the metrics endpoint and can mask the health of the service by hiding actual workload metrics.

Affected Systems

The vulnerability affects the Yopass secret‑sharing service produced by jhaals. All released versions before 14.7.0 are impacted. The issue is fixed in release 14.7.0 and later.

Risk and Exploitability

An unauthenticated external attacker able to craft HTTP requests can exploit this flaw by specifying a large number of distinct method names. The exploitation requires no authentication and can be performed over any open network endpoint exposed by Yopass. The CVSS score of 7.5 indicates a high severity and the lack of an EPSS score means there is no current evidence of exploitation in the wild, but the attack vector is straightforward and could be automated. Because the flaw leads to memory exhaustion and service termination, it constitutes a denial‑of‑service risk. vulnerability is not listed in CISA’s KEV catalog, implying it has not yet been observed as a widely used exploitation.

Generated by OpenCVE AI on October 9, 2026 at 19:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Yopass to version 14.7.0 or later to apply the vendor fix.
  • If an immediate upgrade is not feasible, modify the middleware or firewall configuration to restrict the catch‑all route to standard HTTP methods (GET, POST, PUT, DELETE, etc.) and reject arbitrary method values.
  • Alternatively, disable or limit Prometheus metrics collection, or apply a limit on the number of metric series that can be created to prevent unbounded growth.
  • Continuously monitor system memory usage and Prometheus scrape latency to detect anomalous increases indicative of an ongoing exploitation attempt.

Generated by OpenCVE AI on October 9, 2026 at 19:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 18:15:00 +0000

Type Values Removed Values Added
Description yopass is a service for securely sharing secrets, passwords, and files. Prior to version 14.7.0, the Prometheus metrics middleware in pkg/server/server.go uses the attacker-controlled r.Method value directly as the method label for yopass_http_requests_total and yopass_http_request_duration_seconds. Because the catch-all route accepts arbitrary HTTP method tokens, an unauthenticated remote attacker can submit many unique methods and create metric series that the Prometheus registry never evicts. The resulting monotonic memory growth can OOM-kill the process, while the expanding registry also degrades /metrics scrape latency and can blind monitoring. This issue is fixed in version 14.7.0.
Title yopass Prometheus metrics middleware allows remote memory exhaustion through unbounded method labels
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T19:25:28.403Z

Reserved: 2026-10-08T22:34:49.290Z

Link: CVE-2026-107840

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T18:17:05.953

Modified: 2026-10-09T18:17:05.953

Link: CVE-2026-107840

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T19:30:11Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption