Threat Advisory

OliveTin Unauthenticated Denial of Service Vulnerability

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in OliveTin affecting versions prior to 3000.17.0. These issues encompass remote code execution via OS command injection, unauthorized access to sensitive action logs, and a denial-of-service condition caused by unbounded memory consumption. Exploitation could allow adversaries to execute arbitrary system commands, view restricted data, or render the service completely unavailable. This creates a critical risk environment where operational continuity and data security are severely compromised.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in OliveTin affecting versions prior to 3000.17.0. These issues encompass remote code execution via OS command injection, unauthorized access to sensitive action logs, and a denial-of-service condition caused by unbounded memory consumption. Exploitation could allow adversaries to execute arbitrary system commands, view restricted data, or render the service completely unavailable. This creates a critical risk environment where operational continuity and data security are severely compromised.[emaillocker id="1283"]

  • CVE-2026-67438 with a CVSS score of 6.6 – This vulnerability permits OS command injection by bypassing shell safety checks for regex: argument types, allowing attackers to execute arbitrary commands via POSIX command substitution.
  • CVE-2026-67439 with a CVSS score of 4.3 – This flaw allows users with only execution permissions to read sensitive action output because the synchronous API endpoints fail to enforce the necessary logs permission.
  • CVE-2026-67437 with a CVSS score of 7.5 – An unauthenticated attacker can cause a denial of service by exhausting server memory through repeated requests to the OAuth2 login endpoint, which grows an internal map without bounds.

The combination of remote code execution and denial-of-service capabilities represents a critical threat to organizational infrastructure. Successful exploitation could result in total system compromise and significant operational downtime, demanding immediate prioritization to protect business assets.

RECOMMENDATION:

  • We recommend you to update OliveTin to version 3000.17.0.

REFERENCES:

The following reports contain further technical details:
https://github.com/advisories/GHSA-xc5w-4v5w-7x65
https://github.com/advisories/GHSA-jm28-2wcr-qf3h
https://github.com/advisories/GHSA-xpxj-f2fm-rqch

[/emaillocker]
crossmenu