OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.2, the PasswordHash API endpoint allows unauthenticated users to trigger excessive memory allocation by sending concurrent password hashing requests. By issuing multiple parallel requests, an attacker can exhaust available container memory, leading to service degradation or complete denial of service (DoS). The issue occurs because the endpoint performs computationally and memory-intensive hashing operations without request throttling, authentication requirements, or resource limits. This issue has been patched in version 3000.10.2.

Project Subscriptions

Vendors Products
Olivetin Subscribe
Olivetin Subscribe
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-pc8g-78pf-4xrp OliveTin has Unauthenticated Denial of Service via Memory Exhaustion in PasswordHash API Endpoint
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 06 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Mar 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Olivetin
Olivetin olivetin
Vendors & Products Olivetin
Olivetin olivetin

Thu, 05 Mar 2026 20:00:00 +0000

Type Values Removed Values Added
Description OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.2, the PasswordHash API endpoint allows unauthenticated users to trigger excessive memory allocation by sending concurrent password hashing requests. By issuing multiple parallel requests, an attacker can exhaust available container memory, leading to service degradation or complete denial of service (DoS). The issue occurs because the endpoint performs computationally and memory-intensive hashing operations without request throttling, authentication requirements, or resource limits. This issue has been patched in version 3000.10.2.
Title OliveTin: Unauthenticated Denial of Service via Memory Exhaustion in PasswordHash API Endpoint
Weaknesses CWE-400
CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-03-06T18:02:40.848Z

Reserved: 2026-02-26T18:38:13.889Z

Link: CVE-2026-28342

cve-icon Vulnrichment

Updated: 2026-03-06T18:02:28.622Z

cve-icon NVD

Status : Received

Published: 2026-03-05T20:16:15.837

Modified: 2026-03-06T18:16:17.907

Link: CVE-2026-28342

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-06T15:01:15Z

Weaknesses