Description
Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module. Prior to 0.48.0, Cookie in pkg/cookie/cookie.go parses the total part count from an attacker-controlled multipart cookie name and passes the value to make([]string, numParts) without checking that the value is positive or reasonably bounded. Requests to /validate and /_external-auth-:id reach JWTCacheHandler in pkg/jwtmanager/jwtcache.go, FindJWT in pkg/jwtmanager/jwtmanager.go, and the vulnerable cookie reassembly before JWT validation, so no account or valid session is required. A cookie name such as VouchCookie_1of10000000000 causes an attempted slice allocation of roughly 160 GB and a fatal Go runtime out-of-memory condition, allowing one request to crash the authentication proxy and repeated requests to sustain unavailability. This vulnerability is fixed in 0.48.0.
Published: 2026-09-15
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Out‑of‑Memory Allocation
Action: Patch
AI Analysis

Impact

Vouch Proxy is an SSO and OAuth/OIDC solution for Nginx that uses the auth_request module. In versions older than 0.48.0, the cookie parsing routine in pkg/cookie/cookie.go reads the total number of parts from an attacker‑controlled multipart cookie name and passes that value directly to make([]string, numParts) without validating that the value is positive or bounded. When a request is sent to the /validate or /_external‑auth-:id endpoint, the code reassembles the cookie before JWT validation. An attacker can craft a cookie name such as VouchCookie_1of10000000000, which causes the program to attempt to allocate a slice of roughly 160 GB, leading to a fatal Go runtime out‑of‑memory condition. Because no account or privileged privileges are required, a single HTTP request can crash the authentication proxy, and repeated requests can sustain the service’s unavailability. The vulnerability is fixed in version 0.48.0.

Affected Systems

The affected vendor is vouch, and the product is vouch‑proxy. Versions before 0.48.0, including all releases up to and including 0.47.x, contain the unbounded allocation in the cookie parsing routine. The product is distributed as an open‑source project on GitHub and used in cloud and on‑premises deployments that route OAuth/OIDC authentication through Nginx. Updating to version 0.48.0 or later removes the vulnerability.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, and the EPSS score is below frequency of observed exploitation. The vulnerability is not listed in the CISA KEV catalog, but the easy‑to‑reproduce attack vector—sending a single HTTP request with a crafted multipart cookie—remains a practical Denial‑of‑Service risk. An attacker can trigger a fatal out‑of‑memory condition that crashes the Vouch Proxy process, and repeated requests can keep the service continuously unavailable.

Generated by OpenCVE AI on September 20, 2026 at 15:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Vouch Proxy to version 0.48.0 or later, the release that removes the unbounded allocation.
  • Implement input validation on the cookie name parser to reject names with excessively large part counts or exceed a safe threshold, limiting the maximum number of parts that can be allocated.
  • Configure the network or a web application firewall to rate‑limit or reject requests to the /validate and /_external‑auth‑:id endpoints carrying unusually large or triggered.

Generated by OpenCVE AI on September 20, 2026 at 15:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-qqff-5854-px68 vouch-proxy has an Unbounded Multipart Cookie Allocation DoS
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Vouch
Vouch vouch-proxy
Vendors & Products Vouch
Vouch vouch-proxy

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module. Prior to 0.48.0, Cookie in pkg/cookie/cookie.go parses the total part count from an attacker-controlled multipart cookie name and passes the value to make([]string, numParts) without checking that the value is positive or reasonably bounded. Requests to /validate and /_external-auth-:id reach JWTCacheHandler in pkg/jwtmanager/jwtcache.go, FindJWT in pkg/jwtmanager/jwtmanager.go, and the vulnerable cookie reassembly before JWT validation, so no account or valid session is required. A cookie name such as VouchCookie_1of10000000000 causes an attempted slice allocation of roughly 160 GB and a fatal Go runtime out-of-memory condition, allowing one request to crash the authentication proxy and repeated requests to sustain unavailability. This vulnerability is fixed in 0.48.0.
Title Vouch Proxy: Unbounded Multipart Cookie Allocation DoS
Weaknesses CWE-789
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Vouch Vouch-proxy
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T16:08:18.413Z

Reserved: 2026-06-16T15:13:28.164Z

Link: CVE-2026-55149

cve-icon Vulnrichment

Updated: 2026-09-17T16:08:10.543Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T17:17:21.893

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-55149

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:30:17Z

Weaknesses
  • CWE-789

    Memory Allocation with Excessive Size Value