CVE-2026-28789 is an unauthenticated denial-of-service vulnerability affecting OliveTin versions prior to 3000.10.3 when OAuth2 is enabled. Concurrent requests to the /oauth/login endpoint can trigger a Go runtime panic due to unsynchronized access to a shared map, leading to service termination. This vulnerability has a CVSS score of 7.5 (High), indicating a network-based attack with low complexity and high impact on availability. There is currently no evidence of active exploitation, nor are there public exploit modules or proof-of-concept code available. Community discussion is minimal, with only two mentions identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3000.10.2CPE matchmatch criteria | cpe:2.3:a:olivetin:olivetin:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.