CVE-2026-86734 PUBLISHED

Snipe-IT before 8.7.1 Denial of Service via Unbounded Note Field

Assigner: VulnCheck
Reserved: 08.09.2026 Published: 08.09.2026 Updated: 08.09.2026

Snipe-IT before 8.7.1 fails to validate the length of the note field in the POST /account/accept/{acceptance} endpoint, allowing authenticated users to submit unbounded input that reaches synchronous CommonMark rendering. Attackers can submit large note values to exhaust PHP worker CPU and cause denial of service through resource exhaustion in the markdown parsing pipeline.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor grokability
Product snipe-it
Versions Default: unaffected
  • affected from 0 to 8.7.1 (excl.)
  • Version 8.7.1 is unaffected

Credits

  • PizzaStev3 reporter
  • snipe finder

References

Problem Types

  • Uncontrolled Resource Consumption CWE