THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-v828-m3pf-vq9q (high) — New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging

[GHSA] GHSA-v828-m3pf-vq9q (high) — New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging

highgithub_advisoriesPublished 2026-08-17

GHSA-v828-m3pf-vq9q Severity: high CVE: CVE-2026-64868

New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body reads and full-body logging

## Summary

Unauthenticated payment webhook endpoints could read and log the entire request body before validating the webhook signature. When a payment webhook was enabled, an unauthenticated attacker could send oversized reque

Indicators of compromise

Original source: https://github.com/advisories/GHSA-v828-m3pf-vq9q