216.73.216.233

CVE-2026-28342

· Published 05/03/2026 20:16 · Modified 06/03/2026 18:16

Labels: CVE-2026-28342 2026-03-05CVE-2026-28342CWE-400[email protected]

Essential information

Published
05/03/2026 20:16
Modified
06/03/2026 18:16
Author
Creator
CVSS
7.5 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS metrics

Description

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.10.2, the PasswordHash API endpoint allows unauthenticated users to trigger excessive memory allocation by sending concurrent password hashing requests. By issuing multiple parallel requests, an attacker can exhaust available container memory, leading to service degradation or complete denial of service (DoS). The issue occurs because the endpoint performs computationally and memory-intensive hashing operations without request throttling, authentication requirements, or resource limits. This issue has been patched in version 3000.10.2.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
olivetin / olivetin cpe:2.3:a:olivetin:olivetin:<3000.10.2:*:*:*:*:*:*:*

References