Denial of Service Vulnerability in Vouch Proxy by Vouch
CVE-2026-55149
7.5HIGH
What is CVE-2026-55149?
In Vouch Proxy, a vulnerability in the cookie parsing logic allows an attacker to exploit the system by manipulating a multipart cookie name. This can result in an enormous slice allocation that leads to a Go runtime out-of-memory condition, effectively causing the authentication proxy to crash. The issue affects endpoints including /validate and /_external-auth-:id, allowing attackers to issue requests without the need for a valid account or session. The vulnerability was addressed in version 0.48.0, underscoring the importance of updating to mitigate potential disruptions.
Affected Version(s)
vouch-proxy < 0.48.0
