THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-hh89-3r9w-qj3j (high) — n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint

[GHSA] GHSA-hh89-3r9w-qj3j (high) — n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint

medgithub_advisoriesPublished 2026-09-10

GHSA-hh89-3r9w-qj3j Severity: high CVE: CVE-2026-86075

n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint

## Impact

The OAuth Dynamic Client Registration endpoints validated field sizes only for `redirect_uris`, leaving `client_name` and `grant_types` bounded by presence checks alone. An unauthenticated remote caller could submit arbitrarily large

Indicators of compromise

Original source: https://github.com/advisories/GHSA-hh89-3r9w-qj3j