Description
The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-controlled form fields or submitted content during processing and rendering, which allows a remote attacker to exhaust server resources, prevent administrators from accessing the Entries interface, and trigger HTTP 500 errors via crafted form submissions.
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The updated description clarifies that the Entries component in Brainstorm Force SureForms versions prior to 2.12.3 does not enforce adequate limits on user-controlled form fields during processing and rendering. This flaw enables a remote attacker to submit crafted data that exhausts server resources, causing administrators to lose access to the Entries interface and triggering HTTP 500 errors.

Affected Systems

The vulnerability affects SureForms software from the vendor SureForms, specifically all releases older than version 2.12.3.

Risk and Exploitability

The EPSS score is available and indicates a very low exploitation probability, less than 1% (approximately 0.5%); the CVSS score of 7.5 classifies the vulnerability as high severity. The reported impact of exhausting server resources and producing HTTP 500 errors represents a denial‑of‑service risk. The vulnerability is listed as not included in the CISA KEV catalog. The likely attack vector is remote via web form submissions, no authentication required to trigger the resource exhaustion.

Generated by OpenCVE AI on August 21, 2026 at 17:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply an update to SureForms 2.12.3 or later, which restores proper limits on form input and content processing.
  • If an immediate update is not possible, implement input length validation or rate limiting on the form fields at the application or web‑server level to constrain excessive data submissions.
  • Continuously monitor server CPU, memory, and request rates for abnormal spikes, and configure alerting or automated throttling to mitigate potential impact.

Generated by OpenCVE AI on August 21, 2026 at 17:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description The Entries component in Brainstorm Force SureForms version, less than 2.1.3, does not enforce adequate limits on user-controlled form fields or submitted content during processing and rendering, which allows a remote attacker to exhaust server resources, prevent administrators from accessing the Entries interface, and trigger HTTP 500 errors via crafted form submissions. The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-controlled form fields or submitted content during processing and rendering, which allows a remote attacker to exhaust server resources, prevent administrators from accessing the Entries interface, and trigger HTTP 500 errors via crafted form submissions.

Tue, 18 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770

Tue, 18 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Sureforms
Sureforms sureforms
Vendors & Products Sureforms
Sureforms sureforms

Tue, 18 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770

Tue, 18 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description The Entries component in Brainstorm Force SureForms version, less than 2.1.3, does not enforce adequate limits on user-controlled form fields or submitted content during processing and rendering, which allows a remote attacker to exhaust server resources, prevent administrators from accessing the Entries interface, and trigger HTTP 500 errors via crafted form submissions.
Title SureForms contains an uncontrolled resource consumption vulnerability
References

Subscriptions

Sureforms Sureforms
cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-08-19T13:41:18.259Z

Reserved: 2026-08-10T18:57:53.091Z

Link: CVE-2026-19500

cve-icon Vulnrichment

Updated: 2026-08-18T17:56:15.052Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T16:17:02.647

Modified: 2026-09-03T17:45:20.840

Link: CVE-2026-19500

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T17:15:05Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption