{"id":"CVE-2023-50709","aliases":["GHSA-9759-3276-g2pm"],"url":"https://o3.security/vulnerability/CVE-2023-50709","summary":"Denial of service attack on the cube-api endpoint","details":"### Impact\nIt is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint.\n\n### Patches\nThe issue has been patched in the `v0.34.34` and it's recommended that all users exposing Cube APIs to the public internet upgrade to the latest version to prevent service disruption.\n\n### Workarounds\nThere are currently no workaround for older versions, and the recommendation is to upgrade.\n\n### References\nThe issue was reported by [y0d3n](https://github.com/y0d3n) in our Community Slack and has been promptly patched in the recent update.","published":"2023-12-13T22:00:04.603Z","modified":"2026-08-12T03:51:47.480574854Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@cubejs-backend/api-gateway","fixedVersion":"0.34.34"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/cube-js/cube/releases/tag/v0.34.34"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/50xxx/CVE-2023-50709.json"},{"type":"ADVISORY","url":"https://github.com/cube-js/cube/security/advisories/GHSA-9759-3276-g2pm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-50709"},{"type":"PACKAGE","url":"https://github.com/cube-js/cube"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:47.480574854Z"}}