opencanary is vulnerable to Denial of Service (DoS)
69
Medium Risk
The MongoDB honeypot module reads wire-protocol message-length fields from incoming connections without validating them against a sane maximum, and unpacks framing lengths as signed integers. A single crafted packet with a malformed or oversized length field drives the parser into an unbounded loop that consumes an entire CPU core in the Twisted process, stalling the service for unauthenticated remote clients. The fix validates message and buffer lengths against a maximum size, unpacks length fields as unsigned integers, closes the connection on invalid lengths or buffer-overflow attempts, and adds an idle-connection timeout.
You are affected if you are using a version that falls within the vulnerable range and you have the MongoDB module enabled.
opencanary is vulnerable to Denial of Service (DoS) in versions 0.9.8 - 0.9.8.
Upgrade the opencanary library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant