Back to CVE List

CVE-2026-9137

Vulnerability Description

The CSP report endpoint intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and contribute to resource exhaustion or log flooding.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-400
Source
NVD

External References

Discussion (0)

Add Comment

No comments yet. Be the first!