Description
Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.10.0, BorutaIdentityWeb.UserSettingsController.update/2 atomizes every key of the user-supplied request body via String.to_atom/1 before any validation. Because String.to_atom interns atoms permanently in the BEAM atom table (default cap 1,048,576 atoms; ERL_MAX_ATOMS), any authenticated end user can send PUT /users/settings with a user[<fresh-key>]=... body containing fresh keys per request and exhaust the global VM atom table. Once the table is full, the BEAM aborts with no more index entries in atom_tab and the entire OIDC server (auth, admin, gateway apps in the umbrella) crashes. The route is protected only by require_authenticated_user and a per-IP rate limit of 10 requests/second; a logged-in end user can hit it. The keys are atomized unconditionally before the downstream Accounts.update_user/6 call, so even failing updates contribute to exhaustion. This issue has been patched in version 0.10.0.
Published: 2026-09-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Boruta, an OAuth 2.0 and OpenID Connect authorization server, contains a flaw in the UserSettingsController.update/2 endpoint. The endpoint converts every key in the user‑supplied request body into an atom unconditionally. Because atoms are permanently stored in the BEAM atom table, an attacker can repeatedly send requests with unique keys, rapidly exhausting the table. Once full, the BEAM process aborts, bringing down the entire OIDC server and its associated applications. This results in a denial of service.

Affected Systems

The vulnerability affects malach‑it Boruta‑Server releases prior to version 0.10.0. Any authenticated user of the server can trigger the flaw by issuing a PUT /users/settings request with a uniquely keyed payload. The issue was resolved in version 0.10.0 by removing the unconditional atomization step.

Risk and Exploitability

The CVSS v3.1 base score is 7.1, indicating a high severity. No EPSS score is available and the flaw is not listed in the CISA KEV catalog, but the attack requires only authentication to the server, which a normal user possesses. A per‑IP rate limit of 10 requests per second offers minimal protection, and repeated use will quickly saturate the atom table. The resulting crash affects all components of the umbrella application, making this a high‑risk denial‑of‑service vector for any organization running an affected Boruta server.

Generated by OpenCVE AI on September 3, 2026 at 09:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Boruta‑Server to version 0.10.0 or later where the atomization issue is fixed
  • Disable or restrict access to the user settings update route for unauthenticated or suspicious accounts
  • Implement additional rate limiting or temporarily block access to the PUT /users/settings endpoint if the vulnerability remains unpatched

Generated by OpenCVE AI on September 3, 2026 at 09:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Malach-it
Malach-it boruta-server
Vendors & Products Malach-it
Malach-it boruta-server

Wed, 02 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.10.0, BorutaIdentityWeb.UserSettingsController.update/2 atomizes every key of the user-supplied request body via String.to_atom/1 before any validation. Because String.to_atom interns atoms permanently in the BEAM atom table (default cap 1,048,576 atoms; ERL_MAX_ATOMS), any authenticated end user can send PUT /users/settings with a user[<fresh-key>]=... body containing fresh keys per request and exhaust the global VM atom table. Once the table is full, the BEAM aborts with no more index entries in atom_tab and the entire OIDC server (auth, admin, gateway apps in the umbrella) crashes. The route is protected only by require_authenticated_user and a per-IP rate limit of 10 requests/second; a logged-in end user can hit it. The keys are atomized unconditionally before the downstream Accounts.update_user/6 call, so even failing updates contribute to exhaustion. This issue has been patched in version 0.10.0.
Title Boruta: Authenticated atom-exhaustion DoS in BorutaIdentityWeb.UserSettingsController.update/2
Weaknesses CWE-400
CWE-770
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Malach-it Boruta-server
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-02T19:12:26.718Z

Reserved: 2026-05-28T14:33:01.178Z

Link: CVE-2026-49249

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-02T18:19:28.123

Modified: 2026-09-02T20:17:35.887

Link: CVE-2026-49249

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T10:15:04Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-770

    Allocation of Resources Without Limits or Throttling