216.73.216.233

CVE-2026-9137

· Published 20/05/2026 20:16 · Modified 21/05/2026 16:04

Labels: CVE-2026-9137 2026-05-205a6e4751-2f3f-4070-9419-94fb35b644e8CVE-2026-9137CWE-400

Essential information

Published
20/05/2026 20:16
Modified
21/05/2026 16:04
Author
Creator
CVSS
5.1 MEDIUM (v3) 5.1 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

The CSP report endpoint intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and contribute to resource exhaustion or log flooding.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
5a6e4751-2f3f-4070-9419-94fb35b644e8
NVD
View on NVD

Affected products (CPE)

ProductCPE
* / * cpe:2.3:a:*:*:*:*:*:*:*:*:*:*

References