CVE-2026-31866 impacts openfeature flagd versions prior to 0.14.2, where publicly accessible evaluation endpoints are vulnerable to a denial-of-service (DoS) attack. An unauthenticated attacker can send a single HTTP request with an arbitrarily large body, causing memory exhaustion and process termination (OOMKill) due to unrestricted memory allocation. This vulnerability has a CVSS score of 7.5 HIGH, indicating a critical impact on availability with no confidentiality or integrity concerns. The attack vector is network-based with low complexity and requires no privileges or user interaction. There is currently no evidence of active exploitation, nor are public exploit modules available, and community attention remains low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.14.2CPE matchmatch criteria | cpe:2.3:a:openfeature:flagd:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.