The CSP report endpoint intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and contribute to resource exhaustion or log flooding.
Metrics
Affected Vendors & Products
References
History
Wed, 20 May 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Misp
Misp misp |
|
| Vendors & Products |
Misp
Misp misp |
Wed, 20 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 20 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The CSP report endpoint intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and contribute to resource exhaustion or log flooding. | |
| Title | CSP Report Endpoint Log Flooding via Incorrect Size Limit | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CIRCL
Published:
Updated: 2026-05-20T19:26:46.826Z
Reserved: 2026-05-20T18:42:18.665Z
Link: CVE-2026-9137
Updated: 2026-05-20T19:26:42.606Z
Status : Received
Published: 2026-05-20T20:16:46.177
Modified: 2026-05-20T20:16:46.177
Link: CVE-2026-9137
No data.
OpenCVE Enrichment
Updated: 2026-05-20T21:45:40Z