Vulnerability Description
The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an unauthenticated remote attacker to inject malicious JSON data that can lead to a persistent denial of service condition. Successful exploitation of this vulnerability can disrupt the API Gateway, preventing legitimate API traffic from being processed and impacting complete service availability. The denial of service is persistent, requiring manual intervention to restore normal operations.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wso2 | Api Control Plane | >= 4.5.0, < 4.5.0.55 |
| Wso2 | Api Manager | >= 4.0.0, < 4.0.0.390 |
| Wso2 | Traffic Manager | >= 4.5.0, < 4.5.0.53 |
| Wso2 | Universal Gateway | >= 4.5.0, < 4.5.0.54 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-4249?
CVE-2026-4249 is a vulnerability with a CVSS score of 8.6 (HIGH). The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an unauthenticated remot...
How severe is CVE-2026-4249?
CVE-2026-4249 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-4249?
Check the references section above for vendor advisories and patch information. Affected products include: Wso2 Api Control Plane, Wso2 Api Manager, Wso2 Traffic Manager, Wso2 Universal Gateway.