Description
A vulnerability was identified in evanchiu serverless-todo 1.0.3/2.0.0. Impacted is the function saveTodos of the file src/index.js of the component API Todo Endpoint. Such manipulation of the argument event.body leads to resource consumption. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-13
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Resource Exhaustion / DoS
Action: Apply Mitigation
AI Analysis

Impact

The serverless‑todo API exposes a saveTodos function that processes the event.body payload. The implementation fails to validate the size or content of that payload, allowing an attacker to send data that forces the function to allocate excessive memory or perform extensive computations. The resulting resource consumption can Hang or crash the underlying Lambda function, denying service to legitimate users. The weakness corresponds to resource exhaustion and lack of availability controls (CWE-400, CWE-404).

Affected Systems

The vulnerability affects the evanchiu server Todo endpoint function saveTodos in src/index.js. Versions 1.0.3 and 2.0.0 are susceptible.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, while the EPSS score of <1% signals a low likelihood of exploitation. The issue is not listed in CISA KEV. Based on the description, the attack can be executed remotely: an attacker crafts an event.body payload that is oversized or contains special data patterns, sending it to the Lambda endpoint to trigger excessive resource usage. This path results in denied service for all users due to CPU or memory exhaustion.

Generated by OpenCVE AI on September 15, 2026 at 17:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Enforce strict validation of the event.body payload to reject oversized or malformed data before processing.
  • Implement API request throttling or rate limiting to reduce the impact of repeated exploit attempts.
  • Set up monitoring and alerting for abnormal CPU or memory consumption to detect potential DoS events quickly.
  • Regularly review the vendor’s repository for updates or community patches and apply them when available.

Generated by OpenCVE AI on September 15, 2026 at 17:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in evanchiu serverless-todo 1.0.3/2.0.0. Impacted is the function saveTodos of the file src/index.js of the component API Todo Endpoint. Such manipulation of the argument event.body leads to resource consumption. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
Title evanchiu serverless-todo API Todo Endpoint index.js saveTodos resource consumption
First Time appeared Evanchiu
Evanchiu serverless-todo
Weaknesses CWE-400
CWE-404
CPEs cpe:2.3:a:evanchiu:serverless-todo:*:*:*:*:*:*:*:*
Vendors & Products Evanchiu
Evanchiu serverless-todo
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Evanchiu Serverless-todo
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:59:13.720Z

Reserved: 2026-09-12T17:05:12.567Z

Link: CVE-2026-90582

cve-icon Vulnrichment

Updated: 2026-09-15T13:47:32.171Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T20:16:51.660

Modified: 2026-09-15T15:17:28.967

Link: CVE-2026-90582

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:00:17Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-404

    Improper Resource Shutdown or Release