CVE Explorer
CVE-2026-40481
monetr is a budgeting application for recurring expenses. In versions 1.12.3 and below, the public Stripe webhook endpoint buffers the entire request body into memory before validating the Stripe signature. A remote unauthenticated attacker can send oversized POST payloads to cause uncontrolled memory growth, leading to denial of service. The issue affects deployments with Stripe webhooks enabled and is mitigated if an upstream proxy enforces a request body size limit. This issue has been fixed
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"monetr","vendor":"monetr","versions":[{"status":"affected","version":"< 1.12.4"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:575e17af7f608eb0e03ce6cdf31e48840ce8d3846af8f26f3d249ed2804ec787 · sha256:0da6d3bc90ed2eb3… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":8.2,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:575e17af7f608eb0e03ce6cdf31e48840ce8d3846af8f26f3d249ed2804ec787 · sha256:0da6d3bc90ed2eb3… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-400","description":"CWE-400: Uncontrolled Resource Consumption","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:575e17af7f608eb0e03ce6cdf31e48840ce8d3846af8f26f3d249ed2804ec787 · sha256:0da6d3bc90ed2eb3… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/monetr/monetr/releases/tag/v1.12.4","tags":["x_refsource_MISC"],"url":"https://github.com/monetr/monetr/releases/tag/v1.12.4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:575e17af7f608eb0e03ce6cdf31e48840ce8d3846af8f26f3d249ed2804ec787 · sha256:0da6d3bc90ed2eb3… · /containers/cna/references/1
{"name":"https://github.com/monetr/monetr/security/advisories/GHSA-v7xq-3wx6-fqc2","tags":["x_refsource_CONFIRM"],"url":"https://github.com/monetr/monetr/security/advisories/GHSA-v7xq-3wx6-fqc2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:575e17af7f608eb0e03ce6cdf31e48840ce8d3846af8f26f3d249ed2804ec787 · sha256:0da6d3bc90ed2eb3… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.