Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies. Attackers can send multi-gigabyte request bodies with invalid signatures to trigger out-of-memory conditions and crash the service. | |
| Title | webhook through 2.8.3 Memory Exhaustion via Oversized Request Body | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-14T19:09:50.619Z
Reserved: 2026-09-14T17:33:12.740Z
Link: CVE-2026-91080
Updated: 2026-09-14T19:09:37.742Z
Status : Received
Published: 2026-09-14T18:20:29.760
Modified: 2026-09-14T19:18:14.500
Link: CVE-2026-91080
No data.
OpenCVE Enrichment
No data.