Impact
Vouch Proxy is an SSO and OAuth/OIDC solution for Nginx that uses the auth_request module. In versions older than 0.48.0, the cookie parsing routine in pkg/cookie/cookie.go reads the total number of parts from an attacker‑controlled multipart cookie name and passes that value directly to make([]string, numParts) without validating that the value is positive or bounded. When a request is sent to the /validate or /_external‑auth-:id endpoint, the code reassembles the cookie before JWT validation. An attacker can craft a cookie name such as VouchCookie_1of10000000000, which causes the program to attempt to allocate a slice of roughly 160 GB, leading to a fatal Go runtime out‑of‑memory condition. Because no account or privileged privileges are required, a single HTTP request can crash the authentication proxy, and repeated requests can sustain the service’s unavailability. The vulnerability is fixed in version 0.48.0.
Affected Systems
The affected vendor is vouch, and the product is vouch‑proxy. Versions before 0.48.0, including all releases up to and including 0.47.x, contain the unbounded allocation in the cookie parsing routine. The product is distributed as an open‑source project on GitHub and used in cloud and on‑premises deployments that route OAuth/OIDC authentication through Nginx. Updating to version 0.48.0 or later removes the vulnerability.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, and the EPSS score is below frequency of observed exploitation. The vulnerability is not listed in the CISA KEV catalog, but the easy‑to‑reproduce attack vector—sending a single HTTP request with a crafted multipart cookie—remains a practical Denial‑of‑Service risk. An attacker can trigger a fatal out‑of‑memory condition that crashes the Vouch Proxy process, and repeated requests can keep the service continuously unavailable.
OpenCVE Enrichment
Github GHSA