THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-qqff-5854-px68 (high) — vouch-proxy has an Unbounded Multipart Cookie Allocation DoS

[GHSA] GHSA-qqff-5854-px68 (high) — vouch-proxy has an Unbounded Multipart Cookie Allocation DoS

highgithub_advisoriesPublished 2026-08-20

GHSA-qqff-5854-px68 Severity: high CVE: CVE-2026-55149

vouch-proxy has an Unbounded Multipart Cookie Allocation DoS

## Unbounded Multipart Cookie Allocation DoS in vouch-proxy

### Summary

vouch-proxy v0.47.2 contains an unauthenticated remote denial-of-service vulnerability in its multipart cookie reassembly logic. The `/validate` endpoint parses the total cookie part count directly from the a

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-qqff-5854-px68