Junglewise Threat Intelligence

CVE-2026-4249: WSO2 Multiple Products persistent DoS in throttling event handling

CVE-2026-4249 · Severity: high · CVSS 8.6 · Published 2026-07-06

Executive brief

A vulnerability in several WSO2 API management products could allow an unauthorized person to crash the API Gateway, which is responsible for directing and securing corporate web traffic. By sending specially crafted data, an attacker can cause a persistent service outage that prevents legitimate users and applications from accessing company services. Restoring normal operations requires manual intervention by IT staff, potentially leading to significant business downtime.

Technical details

A denial of service vulnerability exists in the throttling event handling mechanism of multiple WSO2 products due to improper neutralization of input (CWE-707). An unauthenticated remote attacker can submit malicious JSON payloads to the throttling endpoint that the system fails to validate for structure and content. This leads to a persistent DoS condition within the API Gateway, halting the processing of all legitimate API traffic. The vulnerability is mitigated in newer updates by introducing an authentication check for the throttling endpoint and improving payload validation. Patches are available for affected versions including API Manager 3.2.0 through 4.6.0.

Affected products

  • WSO2 API Manager 3.2.0 to 4.6.0
  • WSO2 API Control Plane 4.5.0, 4.6.0
  • WSO2 Traffic Manager 4.5.0, 4.6.0
  • WSO2 Universal Gateway 4.5.0, 4.6.0

Timeline

  • 2026-05-03: advisory: Initial advisory published by WSO2
  • 2026-07-06: disclosed: CVE published to NVD dataset

References

Related threats