Gokapi vulnerable to DoS in E2E Metadata Parser
Description
Published to the GitHub Advisory Database
Mar 13, 2026
Reviewed
Mar 13, 2026
Published by the National Vulnerability Database
Mar 13, 2026
Last updated
Mar 16, 2026
Summary
An API endpoint accepts unbounded request bodies without any size limit. An authenticated user can cause an OOM kill and complete service disruption for all users.
Impact
Any authenticated user can crash the Gokapi server by sending concurrent large payloads.
References