AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-42931

MEDIUM · CVSS 6.5 EPSS 0.38% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The vulnerability in the NPM package Tag Endpoint allows for a Denial of Service (DoS) due to unbounded input handling in the io.ReadAll function, which can lead to resource exhaustion. Organizations utilizing this NPM package should prioritize addressing this issue to prevent potential service disruptions. Developers and system administrators managing applications that depend on this package are particularly at risk and should take immediate action to mitigate the vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-42931
Severity
MEDIUM
CVSS
6.5
EPSS
0.38%

Original NVD Description

Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint