CVE-2026-23881: Missing Context Size Limit Amplification
A method accepts raw byte data, unmarshals it, and appends it to a stateful context without checking the cumulative size of the context data. In policy or template engines, this can allow attackers to mount memory amplification attacks leading to Denial of Service (DoS) via resource exhaustion.
greprules fetch cve-2026-23881-missing-context-size-limit-amplification --engine opengrepDescription
A method accepts raw byte data, unmarshals it, and appends it to a stateful context without checking the cumulative size of the context data. In policy or template engines, this can allow attackers to mount memory amplification attacks leading to Denial of Service (DoS) via resource exhaustion.
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.