Impact
A flaw exists in the handleRequestInternal function of the ExpireSessionsController within PSI Probe. By manipulating the expected input to this handler, an attacker can cause the application to become unresponsive, leading to a denial of service. The vulnerability is categorized as a failure to safely handle a request, identified as CWE-404.
Affected Systems
The weakness affects PSI Probe versions up to and including 5.3.0. Only installations of psi-probe that have not applied a later release are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% suggests very low but non-zero probability of exploitation. The vulnerability has been publicly disclosed and an exploit is available, yet it is not currently listed in the CISA KEV catalog. The attack can be launched remotely, so any exposed PSI Probe instance is a potential target. Absence of a published fix until an update means that unpatched deployments remain exposed to this denial-of-service vector.
OpenCVE Enrichment
Github GHSA