Junglewise Threat Intelligence

CVE-2026-90582: evanchiu serverless-todo resource consumption via unbounded JSON

CVE-2026-90582 · Severity: medium · CVSS 5.3 · Published 2026-09-13

Executive brief

The serverless-todo application is a React Todo backend built with AWS Lambda and DynamoDB. The unauthenticated /api/todos endpoint accepts large JSON payloads without validation, allowing attackers to submit oversized requests that increase Lambda compute time, DynamoDB write costs, and CloudWatch log volume. An attacker can degrade availability and increase operational costs in deployed environments without authentication.

Technical details

The vulnerability is an input validation failure (CWE-400: Uncontrolled Resource Consumption) in the saveTodos() function of src/index.js. The Lambda handler accepts raw POST request bodies, parses them as JSON with minimal validation (only checking if the JSON is well-formed), and writes the entire payload to DynamoDB without enforcing limits on body size, array length, field length, or schema structure. An unauthenticated remote attacker can submit a large JSON array (e.g., 250+ KB) containing many Todo objects with oversized title fields to the endpoint. The application persists this data directly, consuming Lambda CPU/memory, generating DynamoDB write operations, and producing large CloudWatch log entries. The project has been notified but has not yet responded with a fix.

Affected products

  • evanchiu serverless-todo 1.0.3, 2.0.0

Timeline

  • 2026-07-02: disclosed: Issue #10 filed on GitHub
  • 2026-09-13: advisory: CVE-2026-90582 published

References