Arbitrary HTTP Method Exploit in Yopass Service
CVE-2026-107840
What is CVE-2026-107840?
The Yopass service, designed for secure sharing of secrets, passwords, and files, contains a flaw in its Prometheus metrics middleware prior to version 14.7.0. This flaw allows unauthenticated attackers to manipulate HTTP method values used in metrics. By sending arbitrary HTTP method tokens through the catch-all route, attackers can create numerous metric series that will persist indefinitely in the Prometheus registry. This leads to a risk of Out Of Memory (OOM) errors due to unbounded memory growth, which can ultimately crash the Yopass process. Moreover, the inflated metric registry may result in significant latency during metrics scrapes, impairing monitoring capabilities. The vulnerability has been addressed in version 14.7.0.
Affected Version(s)
yopass < 14.7.0
