Impact
The vulnerability manifests as an excessive allocation in the MongoDB module of OpenCanary, caused by improper input validation. Triggering the flaw can consume sufficient memory and CPU resources to stall or crash the application, thereby denying legitimate users access to the canary service. No confidentiality or integrity impact has been reported, and the weakness falls under CWE-20 (Improper Input Validation) and CWE-835 (Infinite Loop).
Affected Systems
Only OpenCanary version 0.9.8 is identified as vulnerable. The product is developed by Thinkst Applied Research, and all other releases and versions are not listed as vulnerable.
Risk and Exploitability
The CVSS score of 6.9 categorises the vulnerability as medium severity, while the EPSS score of less than 1% indicates an extremely low likelihood of exploitation in current threat intelligence. The flaw is not included in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need to interact with the OpenCanary MongoDB module, sending crafted input or repeatedly querying the module, to trigger the excessive allocation. This scenario suggests the risk is chiefly against availability, with a limited probability of automated exploitation.
OpenCVE Enrichment