CVE-2026-84856 | rowboatlabs rowboat up to 0.9.1 Composio Webhook Endpoint route.ts request.text/req.json denial of service

SecurityVulns

A vulnerability described as problematic has been identified in rowboatlabs rowboat up to 0.9.1. The impacted element is the function request.text/req.json of the file apps/rowboat/app/api/composio/webhook/route.ts of the component Composio Webhook Endpoint. The manipulation results in denial of service.

This vulnerability is known as CVE-2026-84856. It is possible to launch the attack remotely. Furthermore, an exploit is available.

Upgrading the affected component is recommended.

The legacy Next.js app was deleted at 0.9.2 rather than patched, leaving no security control behind.VulDB Recent EntriesRead More