Executive brief
Pomerium, an identity-aware proxy, is vulnerable to a denial-of-service attack that can crash the service. An unauthenticated attacker can send a specially crafted, highly compressed data packet to a specific public endpoint, causing the server to exhaust its memory while trying to decompress it. This can lead to service outages, preventing legitimate users from accessing protected applications.
Technical details
A resource exhaustion vulnerability (CWE-400) exists in Pomerium's HPKE V2 URL decoding path within `pkg/hpke/url.go`. The `decodeQueryStringV2` function uses `zstd.DecodeAll` on attacker-controlled data without an output size limit. In stateless authentication deployments (Pomerium Zero), the `/.pomerium/callback` endpoint is reachable without authentication and processes these payloads before validating the sender's identity. By utilizing the publicly available HPKE receiver public key, a remote, unauthenticated attacker can deliver a zstd decompression bomb that causes unbounded memory allocation, leading to a process crash. This issue is fixed in version 0.32.8.
Affected products
- Pomerium Pomerium >= 0.32.6, < 0.32.8
Timeline
- 2026-06-04: advisory: GitHub Advisory published
- 2026-07-15: disclosed: CVE-2026-50285 published
- patched: Fixed in version 0.32.8
References
- https://api.github.com/users/bugbunny-research
- https://github.com/bugbunny-research
- https://api.github.com/users/bugbunny-research/gists%7B/gist_id%7D
- https://api.github.com/users/bugbunny-research/repos
- https://avatars.githubusercontent.com/u/262839898?v=4
- https://api.github.com/users/bugbunny-research/events%7B/privacy%7D