Impact
The exposed webhook reads the entire HTTP request body into memory before it processes any trigger rules. This design allows any unauthenticated user to send a request body that is several gigabytes large, forcing the service to allocate that amount of memory and eventually triggering an out‑of‑memory condition that crashes the process. The weakness is a classic resource exhaustion flaw, identified as CWE‑770.
Affected Systems
The vulnerable version is webhook 2.8.3 from the adnanh:webhook project. All installations running this exact release without an update are affected; earlier releases prior to 2.8.3 do not reproduce the same memory handling logic, but newer releases have been patched.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. Because the attacker does not need authentication and can send arbitrarily large payloads, the exploit is straightforward against any exposed webhook endpoint. The exploit probability (EPSS) score is not available, but the lack of authentication, direct memory allocation, and the ability to cause a crash make the risk significant. The vulnerability is not listed in the CISA KEV catalog at this time.
OpenCVE Enrichment