{"id":"CVE-2026-91080","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-91080","summary":"webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies. Attackers…","details":"webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies. Attackers can send multi-gigabyte request bodies with invalid signatures to trigger out-of-memory conditions and crash the service.","published":"2026-09-14T18:20:29.760","modified":"2026-09-14T18:20:29.760","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/adnanh/webhook"},{"type":"WEB","url":"https://github.com/adnanh/webhook/blob/2.8.3/webhook.go"},{"type":"WEB","url":"https://github.com/adnanh/webhook/issues/756"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/webhook-through-2.8.3-memory-exhaustion-via-oversized-request-body"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-14T18:20:29.760"}}