Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/jhaals/yopass
  4. ›
  5. CVE-2026-107840

CVE-2026-107840: yopass Prometheus metrics middleware allows remote memory exhaustion through unbounded method labels

October 9, 2026

The Prometheus metrics middleware in pkg/server/server.go used r.Method directly as a label value on request counter and duration histogram metrics. Since the mux catch-all route matches any HTTP method, an unauthenticated attacker can send requests with arbitrary method strings (e.g. curl -X “M1” http://host/), each creating new counter and histogram time series in the Prometheus registry. The registry’s internal maps never evict entries.

An attacker issuing requests with unique method values causes monotonic memory growth until the process is OOM-killed. Additionally, /metrics scrape latency degrades proportionally, eventually timing out and blinding monitoring.

Remediation: Upgrade to 14.7.0 or later, which clamps the method label to a fixed allowlist (GET, POST, PUT, DELETE, OPTIONS, HEAD, CONNECT, TRACE) and maps everything else to other.

References

  • github.com/advisories/GHSA-6r69-c6wg-7g8m
  • github.com/jhaals/yopass/commit/61e31ead04a4fc27ce80bed226af41c7c0426ccf
  • github.com/jhaals/yopass/commit/78d0c14f7085048130199662a2ec8a18ec8d6ebb
  • github.com/jhaals/yopass/pull/3773
  • github.com/jhaals/yopass/releases/tag/14.7.0
  • github.com/jhaals/yopass/security/advisories/GHSA-6r69-c6wg-7g8m
  • nvd.nist.gov/vuln/detail/CVE-2026-107840

Code Behaviors & Features

Detect and mitigate CVE-2026-107840 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 0.0.0-20260727191436-61e31ead04a4

Fixed versions

  • 0.0.0-20260727191436-61e31ead04a4

Solution

Upgrade to version 0.0.0-20260727191436-61e31ead04a4 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-400: Uncontrolled Resource Consumption

Source file

go/github.com/jhaals/yopass/CVE-2026-107840.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sun, 11 Oct 2026 12:21:40 +0000.