Snipe-IT before 8.7.1 fails to validate the length of the note field in the POST /account/accept/{acceptance} endpoint, allowing authenticated users to submit unbounded input that reaches synchronous CommonMark rendering. Attackers can submit large note values to exhaust PHP worker CPU and cause denial of service through resource exhaustion in the markdown parsing pipeline.
References
| Link | Resource |
|---|---|
| https://github.com/grokability/snipe-it/commit/66770cfe20cb135e2b7022c7a83d01e6783c914a | Patch |
| https://github.com/grokability/snipe-it/security/advisories/GHSA-4vcv-fc5x-jjwv | Mitigation Patch Vendor Advisory |
| https://www.vulncheck.com/advisories/snipe-it-before-8.7.1-denial-of-service-via-unbounded-note-field | Patch Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-09-08 16:18
Updated : 2026-09-10 16:18
NVD link : CVE-2026-86734
Mitre link : CVE-2026-86734
CVE.ORG link : CVE-2026-86734
JSON object : View
Products Affected
snipeitapp
- snipe-it
CWE
CWE-400
Uncontrolled Resource Consumption
