THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-r5pq-6chh-j3xp (high) — Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter

[GHSA] GHSA-r5pq-6chh-j3xp (high) — Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter

highgithub_advisoriesPublished 2026-08-21

GHSA-r5pq-6chh-j3xp Severity: high CVE: CVE-2026-63462

Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter

## Summary

An unauthenticated `POST` to any OpenAPI-validated endpoint, including the anonymous `POST /edge/validate` and `POST /edge/issue-token`, crashes the entire Unleash server with one request body of deeply-nested JSON.

When request-body validation fa

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-r5pq-6chh-j3xp