HIGH · 8.6

CVE-2026-4249

The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an unauthenticated remot...

Vulnerability Description

The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an unauthenticated remote attacker to inject malicious JSON data that can lead to a persistent denial of service condition. Successful exploitation of this vulnerability can disrupt the API Gateway, preventing legitimate API traffic from being processed and impacting complete service availability. The denial of service is persistent, requiring manual intervention to restore normal operations.

CVSS Score

8.6

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
Wso2Api Control Plane>= 4.5.0, < 4.5.0.55
Wso2Api Manager>= 4.0.0, < 4.0.0.390
Wso2Traffic Manager>= 4.5.0, < 4.5.0.53
Wso2Universal Gateway>= 4.5.0, < 4.5.0.54

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-4249?

CVE-2026-4249 is a vulnerability with a CVSS score of 8.6 (HIGH). The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an unauthenticated remot...

How severe is CVE-2026-4249?

CVE-2026-4249 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2026-4249?

Check the references section above for vendor advisories and patch information. Affected products include: Wso2 Api Control Plane, Wso2 Api Manager, Wso2 Traffic Manager, Wso2 Universal Gateway.