THREAT OPS › Threat News › [GHSA] GHSA-r5pq-6chh-j3xp (high) — Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter
[GHSA] GHSA-r5pq-6chh-j3xp (high) — Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter
GHSA-r5pq-6chh-j3xp Severity: high CVE: CVE-2026-63462
Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter
## Summary
An unauthenticated `POST` to any OpenAPI-validated endpoint, including the anonymous `POST /edge/validate` and `POST /edge/issue-token`, crashes the entire Unleash server with one request body of deeply-nested JSON.
When request-body validation fa
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-63462cve
- https://www.turingpoint.deurl
- jan@turingpoint.deemail
Original source: https://github.com/advisories/GHSA-r5pq-6chh-j3xp