Executive brief
SigningHub is a digital signature platform used by organizations to securely sign and manage documents. A vulnerability in the document upload component allows an attacker to repeatedly upload files without restriction. This can lead to a denial-of-service (DoS) condition, making the platform unavailable to legitimate users by exhausting server resources or disk space.
Technical details
A resource exhaustion vulnerability exists in the SigningHub Upload Document API (/Home/UploadStreamDocument). The component fails to implement rate limiting or throttling on file uploads. A remote attacker can exploit this by rapidly uploading a large volume of files, leading to disk space depletion, high CPU/memory load, and overall service degradation. The vulnerability is confirmed in version 8.6.8 and earlier; remediation involves upgrading to a version later than 8.6.8 or implementing server-side rate limiting.
Affected products
- Ascertia SigningHub <= 8.6.8
Timeline
- 2025-10-20: disclosed
- 2025-10-20: advisory