Impact
Snipe-IT versions earlier than 8.7.1 allow authenticated users to submit notes with no length restriction to the POST /account/accept/{acceptance} endpoint. The unbounded input is processed by the CommonMark renderer synchronously, which can consume excessive CPU resources. As a result, an attacker can force the PHP worker to become unresponsive, causing a denial of service to legitimate users. The weakness corresponds to CWE-400, an uncontrolled resource consumption flaw.
Affected Systems
The vulnerability affects all installations of Snipe‑IT with the snipe-it application (snipeitapp:snipe‑it). Versions prior to 8.7.1 are impacted. No specific minor or patch level details are supplied beyond the version cutoff.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability constitutes a high‑severity issue. EPSS data is unavailable and the vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed exploitation at the time of this analysis. The attack requires authenticated access to the affected endpoint, so it is likely an insider or compromised user scenario. Once an attacker submits a large note, the resource exhaustion occurs synchronously, quickly exhausting PHP worker CPU and leading to service unavailability.
OpenCVE Enrichment