CVE 8.2 HIGH

monetr: Unauthenticated Stripe webhook reads attacker-sized request bodies before signature validation_CVE-2026-40481

8.2 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Description

monetr is a budgeting application for recurring expenses. In versions 1.12.3 and below, the public Stripe webhook endpoint buffers the entire request body into memory before validating the Stripe signature. A remote unauthenticated attacker can send oversized POST payloads to cause uncontrolled memory growth, leading to denial of service. The issue affects deployments with Stripe webhooks enabled and is mitigated if an upstream proxy enforces a request body size limit. This issue has been fixed in version 1.12.4.

Basic Information

ID CVE-2026-40481
Source GitHub_M
Published Apr 17, 2026 at 22:54

Affected Product

Vendor monetr
Product monetr
Version < 1.12.4
Affected Versions monetr monetr < 1.12.4

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.