CVE-2026-107840
Received Received - Intake

Prometheus Metrics DoS via Unbounded HTTP Method in yopass

Vulnerability report for CVE-2026-107840, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

yopass is a service for securely sharing secrets, passwords, and files. Prior to version 14.7.0, the Prometheus metrics middleware in pkg/server/server.go uses the attacker-controlled r.Method value directly as the method label for yopass_http_requests_total and yopass_http_request_duration_seconds. Because the catch-all route accepts arbitrary HTTP method tokens, an unauthenticated remote attacker can submit many unique methods and create metric series that the Prometheus registry never evicts. The resulting monotonic memory growth can OOM-kill the process, while the expanding registry also degrades /metrics scrape latency and can blind monitoring. This issue is fixed in version 14.7.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jhaals yopass < 14.7.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the yopass service before version 14.7.0. The Prometheus metrics middleware uses attacker-controlled HTTP method values directly as labels for metrics. Since the catch-all route accepts any HTTP method, an attacker can send requests with unique methods, creating unbounded metric series in Prometheus. This causes memory exhaustion, increased latency in metrics scraping, and potential monitoring blindness.

Detection Guidance

To detect this vulnerability, monitor Prometheus metrics for unbounded label cardinality in yopass_http_requests_total and yopass_http_request_duration_seconds. Check for an excessive number of unique HTTP method labels. Use commands like 'curl http://<yopass-server>:<port>/metrics' to inspect metrics and 'watch -n 1 'curl -s http://<yopass-server>:<port>/metrics | grep yopass_http_requests_total'' to track label growth over time.

Impact Analysis

An unauthenticated remote attacker can exploit this to cause the yopass service to run out of memory, leading to crashes. It also degrades performance of the /metrics endpoint, increasing scrape latency and potentially causing timeouts. This impacts availability and monitoring capabilities of the service.

Compliance Impact

This vulnerability primarily impacts system availability and monitoring integrity rather than directly violating GDPR or HIPAA compliance. The uncontrolled resource consumption could lead to service disruptions, which may indirectly affect availability requirements in both regulations. However, the core issue is an availability risk (CWE-400) rather than a data protection or privacy violation.

Mitigation Strategies

Upgrade yopass to version 14.7.0 or later to fix the metrics middleware issue. If upgrading is not immediately possible, restrict access to the /metrics endpoint or disable Prometheus metrics temporarily. Monitor system memory usage for signs of OOM conditions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107840. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart