CVE-2026-16551
Received Received - Intake

Denial-of-Service in OpenCanary MongoDB Module via Excessive Allocation

Vulnerability report for CVE-2026-16551, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-22

Last updated on: 2026-07-22

Assigner: 0f2be0ad-3469-4e56-b38f-4eb96719b425

Description

Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB module) allows Excessive Allocation. This issue affects OpenCanary 0.9.8 only.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-22
Last Modified
2026-07-22
Generated
2026-07-22
AI Q&A
2026-07-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
thinkst opencanary to 0.9.9 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-835 The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-16551 is a Denial-of-Service (DoS) vulnerability in the MongoDB module of OpenCanary version 0.9.8. It allows a single malicious packet to trigger an infinite loop in the Twisted process, consuming all CPU time on a core and causing system freezes or severe performance issues.

Detection Guidance

Check OpenCanary version with 'opencanaryd --version'. If running 0.9.8, the MongoDB module may be vulnerable. Monitor CPU usage spikes on systems running OpenCanary 0.9.8 with the MongoDB module enabled.

Impact Analysis

This vulnerability can cause your system to freeze or become unresponsive due to excessive CPU usage. It may lead to service disruptions, degraded performance, or complete downtime for systems running OpenCanary 0.9.8 with the MongoDB module enabled.

Mitigation Strategies

Upgrade OpenCanary to version 0.9.9 or later. As a temporary fix, disable the MongoDB module by setting 'mongodb.enabled: false' in opencanary.conf and restarting the service.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16551. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart