Back

HIGH

Unauthenticated Denial of Service via Unbounded Activity-Timeline Range in CTI-Transmute

Published Aug 3, 2026

Description

CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endpoint. The endpoint accepts a user-controlled days query parameter that was not restricted to a reasonable range.

A remote, unauthenticated attacker could submit an excessively large value for this parameter, causing the application to retrieve and process activity data over an arbitrarily large period. This could consume excessive database, CPU, or memory resources, delay the processing of concurrent requests, or trigger an internal server error. Repeated requests could further degrade the availability of the CTI-Transmute website.

The vulnerability is corrected by clamping the requested timeline range to a minimum of one day and a maximum of 1,095 days.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CIRCL
Published Aug 3, 2026
Updated Aug 3, 2026
Reserved Aug 3, 2026
CISA Vulnrichment
Updated Aug 3, 2026
NVD
Status Deferred
Modified Aug 26, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner CIRCL
Published Aug 3, 2026
Updated Aug 3, 2026
Exploited since n/a
EUVD-2026-52255