Executive brief
Snipe-IT is an open-source asset management system used by organizations to track IT equipment and hardware. A flaw in the asset acceptance workflow allows authenticated users to submit extremely long notes that trigger excessive CPU consumption during markdown processing, causing the web application to become unresponsive and denying service to legitimate users.
Technical details
The vulnerability is an input validation bypass (CWE-1284) combined with uncontrolled resource consumption (CWE-400) in the POST /account/accept/{acceptance} endpoint. The note field lacks server-side length validation before being persisted and passed to the AcceptanceItemDeclinedNotification, where it undergoes synchronous markdown rendering via league/commonmark 2.8.2. By default, Snipe-IT uses a synchronous queue driver, causing parser CPU work to block the request cycle. An authenticated attacker with a pending checkout acceptance can submit notes exceeding 80,000 bytes, causing 2.6+ seconds of CPU exhaustion per request. The fix (v8.7.1) upgrades league/commonmark to 2.9.0+ and adds server-side validation (max:1000) on the note field before persistence or notification.
Affected products
- Snipe-IT Snipe-IT before 8.7.1
Timeline
- 2026-08-24: disclosed: GHSA-4vcv-fc5x-jjwv published on GitHub Security Advisories
- 2026-08-11: patched: Fix committed (66770cfe); v8.7.1 released
- 2026-09-08: advisory: CVE-2026-86734 published on NVD