Arbitrary HTTP Method Exploit in Yopass Service
CVE-2026-107840

7.5HIGH

Key Information:

Vendor

Jhaals

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-107840?

The Yopass service, designed for secure sharing of secrets, passwords, and files, contains a flaw in its Prometheus metrics middleware prior to version 14.7.0. This flaw allows unauthenticated attackers to manipulate HTTP method values used in metrics. By sending arbitrary HTTP method tokens through the catch-all route, attackers can create numerous metric series that will persist indefinitely in the Prometheus registry. This leads to a risk of Out Of Memory (OOM) errors due to unbounded memory growth, which can ultimately crash the Yopass process. Moreover, the inflated metric registry may result in significant latency during metrics scrapes, impairing monitoring capabilities. The vulnerability has been addressed in version 14.7.0.

Affected Version(s)

yopass < 14.7.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.