CVE-2026-107840 | jhaals yopass up to 14.6.x Prometheus metrics middleware pkg/server/server.go Method resource consumption

SecurityVulns

A vulnerability identified as problematic has been detected in jhaals yopass up to 14.6.x. This issue affects some unknown processing of the file pkg/server/server.go of the component Prometheus metrics middleware. The manipulation of the argument Method leads to resource consumption.

This vulnerability is documented as CVE-2026-107840. The attack can be initiated remotely. There is not any exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More