THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-fmgp-q6jx-gg3x (high) — KubeVela Terraform remote loader DoS via unbounded file read

[GHSA] GHSA-fmgp-q6jx-gg3x (high) — KubeVela Terraform remote loader DoS via unbounded file read

highgithub_advisoriesPublished 2026-08-28

GHSA-fmgp-q6jx-gg3x Severity: high CVE: CVE-2026-55108

KubeVela Terraform remote loader DoS via unbounded file read

### Summary

KubeVela's Terraform remote configuration loader can be abused to make `vela-core` read an unbounded byte stream into memory, causing an out-of-memory kill and a control-plane denial of service.

The issue is reachable when a user with permission to create or update a

Indicators of compromise

Original source: https://github.com/advisories/GHSA-fmgp-q6jx-gg3x