{"id":"CVE-2026-67437","summary":"OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)","details":"OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_auth_oauth2.go OAuth2 login handler stores per-login state in the registeredStates map on every /oauth/login request without expiring, deleting, or bounding entries, allowing an unauthenticated attacker to exhaust memory and cause a denial of service. This issue is fixed in version 3000.17.0.","aliases":["GHSA-xpxj-f2fm-rqch","GO-2026-6146"],"modified":"2026-09-09T18:26:41.663362245Z","published":"2026-07-29T20:43:05.167Z","related":["openSUSE-SU-2026:21761-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-400","CWE-401","CWE-770"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67437.json"},"references":[{"type":"WEB","url":"https://github.com/OliveTin/OliveTin/releases/tag/3000.17.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67437.json"},{"type":"ADVISORY","url":"https://github.com/OliveTin/OliveTin/security/advisories/GHSA-xpxj-f2fm-rqch"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67437"},{"type":"FIX","url":"https://github.com/OliveTin/OliveTin/commit/ec114e95d297b806c3ca0c37bc139b3c9c517b3f"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/olivetin/olivetin","events":[{"introduced":"45f9c18bc3eed38209f14607de4f6eb7c8bee096"},{"fixed":"ec114e95d297b806c3ca0c37bc139b3c9c517b3f"},{"fixed":"d0075a7a8d44028793ea3384b34062b940841f24"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"3000.0.0"},{"fixed":"3000.17.0"}]}}],"versions":["3000.16.2","3000.16.1","3000.16.0","3000.15.0","3000.14.0","3000.13.0","3000.11.1","3000.12.0","3000.11.4","3000.11.3","3000.11.2","3000.11.0","3000.10.2","3000.10.1","3000.10.0","3000.9.4","3000.9.1","3000.9.0","3000.8.0","3000.7.0","3000.6.0","3000.5.0","3000.4.0","3000.3.2","3000.3.1","3000.3.0","3000.2.1","3000.2.0","3000.1.2","3000.1.1","3000.1.0","3000.0.2","3000.0.1","3000.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-67437.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}