Impact
n8n's OAuth Dynamic Client Registration endpoint does not enforce limits on the client_name and grant_types fields, allowing unauthenticated callers to send arbitrarily large values. The resulting oversized entries are written to the oauth_clients table without truncation, consuming database storage until the database is exhausted and the service becomes unavailable. This reflects a resource exhaustion flaw (CWE-770).
Affected Systems
This issue affects all installations of the n8n workflow automation platform running any version older than 2.37.7 or 2.38.2. The affected component is the OAuth server module located at packages/cli/src/modules/oauth-server/oauth-server.service.ts. Users who rely on n8n's default OAuth client configuration or open registration are at risk.
Risk and Exploitability
With a CVSS score of 8.7, the vulnerability represents a high severity problem. The EPSS score is not available, so the current likelihood of exploitation is uncertain, but the lack of authentication and the nature of the resource exhaustion attack make it plausible for attackers to exploit it remotely over the network. The vulnerability is not listed in the CISA KEV catalog at this time. Applying the vendor’s patch that caps client_name and grant_types length in releases 2.37.7 and 2.38.2 and disabling dynamic client registration until the fix is in place are the recommended mitigations.
OpenCVE Enrichment
Github GHSA