Impact
The serverless‑todo API exposes a saveTodos function that processes the event.body payload. The implementation fails to validate the size or content of that payload, allowing an attacker to send data that forces the function to allocate excessive memory or perform extensive computations. The resulting resource consumption can Hang or crash the underlying Lambda function, denying service to legitimate users. The weakness corresponds to resource exhaustion and lack of availability controls (CWE-400, CWE-404).
Affected Systems
The vulnerability affects the evanchiu server Todo endpoint function saveTodos in src/index.js. Versions 1.0.3 and 2.0.0 are susceptible.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while the EPSS score of <1% signals a low likelihood of exploitation. The issue is not listed in CISA KEV. Based on the description, the attack can be executed remotely: an attacker crafts an event.body payload that is oversized or contains special data patterns, sending it to the Lambda endpoint to trigger excessive resource usage. This path results in denied service for all users due to CPU or memory exhaustion.
OpenCVE Enrichment