Skip to content
Threat Feed
low advisory

Unbounded Memory Exhaustion in yopass Prometheus Metrics Middleware

An unauthenticated remote denial-of-service vulnerability in yopass allows attackers to trigger monotonic memory growth by injecting arbitrary HTTP method strings into Prometheus metrics labels.

CVE search metadata

CVE search record: CVE-2026-107840. Severity: high. CVSS: 7.5. KEV: no. Product: yopass (< 0.0.0-20260727191436-61e31ead04a4). Brief: Unbounded Memory Exhaustion in yopass Prometheus Metrics Middleware. Brief link: https://feed.craftedsignal.io/briefs/2026-10-yopass-prometheus-dos/

The yopass server, specifically within its Prometheus metrics middleware in pkg/server/server.go, is vulnerable to a denial-of-service (DoS) attack caused by improper handling of HTTP request method labels. The application incorrectly uses the raw HTTP request method string as a label for Prometheus counter and histogram metrics. Because the catch-all routing mechanism accepts arbitrary method strings from an unauthenticated request, an attacker can flood the server with requests using unique, randomized method strings.

Each unique method creates a new entry in the Prometheus registry's internal data structures. As these registry maps lack an eviction mechanism, each injection consumes additional memory. Continued exploitation results in unbounded memory growth, eventually triggering an OOM (Out-of-Memory) kill of the yopass process. Furthermore, the registry growth causes severe degradation of the /metrics scraping latency, preventing visibility and monitoring before the service crashes. This vulnerability is tracked as CVE-2026-107840 and affects versions prior to 0.0.0-20260727191436-61e31ead04a4.

Impact

Successful exploitation results in a persistent denial-of-service condition, rendering the yopass instance unavailable. The impact includes the loss of secret sharing capabilities and the blindness of infrastructure monitoring due to the degradation and eventual timeout of the /metrics scrape endpoint. Given the ease of exploitation via simple HTTP requests, the risk to availability for internet-facing yopass instances is significant.

Recommendation

Prioritize upgrading yopass to version 14.7.0 or later, which implements an allowlist for HTTP methods (GET, POST, PUT, DELETE, OPTIONS, HEAD, CONNECT, TRACE) and sanitizes unknown methods by mapping them to an 'other' label.

Mitigations

Upgrade yopass to version 14.7.0 or later

immediate IT Operations

CVE-2026-107840