


Perceptive Security
SOC/SIEM Consultancy

OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_auth_oauth2.g…
Published:
28 juli 2026 om 22:00:00
Alert date:
29 juli 2026 om 22:00:53
Source:
nvd.nist.gov
Web Technologies, Identity & Access
A denial-of-service vulnerability exists in OliveTin versions 3000.0.0 through 3000.17.0. The OAuth2 login handler in restapi_auth_oauth2.go stores per-login state entries in the registeredStates map on every /oauth/login request without any expiration, deletion, or size bounding. An unauthenticated attacker can repeatedly send requests to this endpoint, causing unbounded memory growth and ultimately exhausting system memory. This results in a denial of service condition. No authentication is required to exploit this vulnerability. The issue has been patched in version 3000.17.0. Users are advised to upgrade immediately to mitigate the risk.
Technical details
Mitigation steps:
Affected products:
OliveTin 3000.0.0 - 3000.17.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67437
https://github.com/OliveTin/OliveTin/commit/ec114e95d297b806c3ca0c37bc139b3c9c517b3f
https://github.com/OliveTin/OliveTin/releases/tag/3000.17.0
https://github.com/OliveTin/OliveTin/security/advisories/GHSA-xpxj-f2fm-rqch
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
