THREAT OPS › Threat News › [GHSA] GHSA-hh89-3r9w-qj3j (high) — n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint
[GHSA] GHSA-hh89-3r9w-qj3j (high) — n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint
GHSA-hh89-3r9w-qj3j Severity: high CVE: CVE-2026-86075
n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint
## Impact
The OAuth Dynamic Client Registration endpoints validated field sizes only for `redirect_uris`, leaving `client_name` and `grant_types` bounded by presence checks alone. An unauthenticated remote caller could submit arbitrarily large
Indicators of compromise
- CVE-2026-86075cve
Original source: https://github.com/advisories/GHSA-hh89-3r9w-qj3j