Description
webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies. Attackers can send multi-gigabyte request bodies with invalid signatures to trigger out-of-memory conditions and crash the service.
Published: 2026-09-14
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory Exhaustion causing service disruption
Action: Immediate Patch
AI Analysis

Impact

The exposed webhook reads the entire HTTP request body into memory before it processes any trigger rules. This design allows any unauthenticated user to send a request body that is several gigabytes large, forcing the service to allocate that amount of memory and eventually triggering an out‑of‑memory condition that crashes the process. The weakness is a classic resource exhaustion flaw, identified as CWE‑770.

Affected Systems

The vulnerable version is webhook 2.8.3 from the adnanh:webhook project. All installations running this exact release without an update are affected; earlier releases prior to 2.8.3 do not reproduce the same memory handling logic, but newer releases have been patched.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity. Because the attacker does not need authentication and can send arbitrarily large payloads, the exploit is straightforward against any exposed webhook endpoint. The exploit probability (EPSS) score is not available, but the lack of authentication, direct memory allocation, and the ability to cause a crash make the risk significant. The vulnerability is not listed in the CISA KEV catalog at this time.

Generated by OpenCVE AI on September 15, 2026 at 12:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade webhook to the latest release that contains the memory‑allocation patch.
  • Configure an upstream reverse proxy or firewall to reject HTTP request bodies that exceed a sane size limit (e.g., 10 MB) to prevent oversized requests from reaching the service.
  • Set up monitoring and alerts for abnormal memory usage or “out‑of‑memory” errors to detect and respond to attempted exploitation promptly.

Generated by OpenCVE AI on September 15, 2026 at 12:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Adnanh
Adnanh webhook
Vendors & Products Adnanh
Adnanh webhook

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies. Attackers can send multi-gigabyte request bodies with invalid signatures to trigger out-of-memory conditions and crash the service.
Title webhook through 2.8.3 Memory Exhaustion via Oversized Request Body
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:08.500Z

Reserved: 2026-09-14T17:33:12.740Z

Link: CVE-2026-91080

cve-icon Vulnrichment

Updated: 2026-09-14T19:09:37.742Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:20:29.760

Modified: 2026-09-23T17:17:44.733

Link: CVE-2026-91080

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:02:23Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling