CVE-2026-27460 is a Denial of Service vulnerability in Tandoor Recipes, a recipe management and meal planning application, affecting versions prior to 2.6.5. The flaw exists in the recipe import functionality, where authenticated users can exploit ZIP Bomb techniques by uploading oversized ZIP files to crash the server or severely degrade its performance. This vulnerability has been remediated in version 2.6.5 and later. The vulnerability carries a CVSS score of 6.5 (Medium severity) with a network-based attack vector requiring low complexity and valid user authentication. The impact is limited to availability, with no confidentiality or integrity compromise. While the attack requires authenticated access, the ease of execution and potential for significant service disruption make it a notable operational risk for Tandoor Recipes deployments. Exploitation appears minimal at this time, with no active exploitation reported in the wild or formal exploit code in public circulation. The vulnerability is not tracked on the CISA KEV catalog, and community attention remains low, as indicated by the inactive Hot List status. Organizations running Tandoor Recipes should prioritize upgrading to version 2.6.5 to mitigate this risk, particularly in environments where user authentication is widely distributed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.6.5CPE matchmatch criteria | cpe:2.3:a:tandoor:recipes:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.