Junglewise Threat Intelligence

CVE-2026-50285: Pomerium is an identity and context-aware access proxy. Prior to 0.32.8, decodeQueryStringV2 in pkg/hpke/url.go performs zstd decompression

CVE-2026-50285 · Severity: high · CVSS 7.5 · Published 2026-09-17

Technologies: github.com/pomerium/pomerium (Go). Vendors: Go.

Executive brief

Pomerium, an identity-aware proxy, is vulnerable to a denial-of-service attack that can crash the service. An unauthenticated attacker can send a specially crafted, highly compressed data packet to a specific public endpoint, causing the server to exhaust its memory while trying to decompress it. This can lead to service outages, preventing legitimate users from accessing protected applications.

Technical details

A resource exhaustion vulnerability (CWE-400) exists in Pomerium's HPKE V2 URL decoding path within `pkg/hpke/url.go`. The `decodeQueryStringV2` function uses `zstd.DecodeAll` on attacker-controlled data without an output size limit. In stateless authentication deployments (Pomerium Zero), the `/.pomerium/callback` endpoint is reachable without authentication and processes these payloads before validating the sender's identity. By utilizing the publicly available HPKE receiver public key, a remote, unauthenticated attacker can deliver a zstd decompression bomb that causes unbounded memory allocation, leading to a process crash. This issue is fixed in version 0.32.8.

Affected products

  • Pomerium Pomerium >= 0.32.6, < 0.32.8

Timeline

  • 2026-06-04: advisory: GitHub Advisory published
  • 2026-07-15: disclosed: CVE-2026-50285 published
  • patched: Fixed in version 0.32.8

References

Related threats