THREAT OPS › Threat News › [GHSA] GHSA-qqff-5854-px68 (high) — vouch-proxy has an Unbounded Multipart Cookie Allocation DoS
[GHSA] GHSA-qqff-5854-px68 (high) — vouch-proxy has an Unbounded Multipart Cookie Allocation DoS
GHSA-qqff-5854-px68 Severity: high CVE: CVE-2026-55149
vouch-proxy has an Unbounded Multipart Cookie Allocation DoS
## Unbounded Multipart Cookie Allocation DoS in vouch-proxy
### Summary
vouch-proxy v0.47.2 contains an unauthenticated remote denial-of-service vulnerability in its multipart cookie reassembly logic. The `/validate` endpoint parses the total cookie part count directly from the a
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-55149cve
- http://127.0.0.1:19090/validateurl
- http://vouch.github.iourl
- https://indielogin.com/authurl
- http://vouch.github.io:9090/authurl
- http://{host}:{port}/validateurl
Original source: https://github.com/advisories/GHSA-qqff-5854-px68