Executive brief
webhook is a lightweight server that listens for incoming HTTP requests and triggers shell commands based on configured rules. A flaw in versions through 2.8.3 causes the server to read and buffer entire request bodies into memory before validating the request signature, allowing unauthenticated attackers to crash the service by sending large payloads with invalid signatures. An attacker can trigger denial-of-service conditions without needing valid credentials or signatures.
Technical details
The vulnerability is a denial-of-service (DoS) due to unbounded memory consumption (CWE-400). The root cause is that webhook reads the complete HTTP request body into memory before evaluating trigger rules and validating webhook signatures. An unauthenticated, network-accessible attacker can exploit this by sending multi-gigabyte request bodies with invalid signatures, causing the server to exhaust available memory and crash. No authentication or valid signature is required; the malicious request need only reach the webhook endpoint. The vulnerability affects all versions through 2.8.3.
Affected products
- adnanh webhook through 2.8.3
Timeline
- 2026-09-14: disclosed