Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40481

25
FAUCET Score

CVE-2026-40481 is a denial of service vulnerability in monetr, a budgeting application, affecting versions 1.12.3 and below. The flaw exists in the public Stripe webhook endpoint, which fails to validate webhook signatures before buffering request bodies into memory. An unauthenticated remote attacker can exploit this by sending oversized POST payloads to cause uncontrolled memory consumption and application unavailability. The vulnerability only impacts deployments with Stripe webhooks enabled and can be mitigated through upstream proxy request size limits until patching to version 1.12.4 is available. The attack vector is network-based and requires minimal complexity, as an attacker simply needs to send crafted HTTP requests without authentication. While the CVSS score is not provided, the FAUCET Risk Score of 40.0/100 and EPSS of 0.00185 indicate low to moderate severity with limited widespread risk. The primary impact is availability, through denial of service caused by memory exhaustion, rather than confidentiality or integrity compromise. There is no evidence of active exploitation, as the vulnerability is not listed in the Known Exploited Vulnerabilities catalog and remains on the inactive Hot List. The low EPSS score suggests minimal community attention or exploit development. Organizations should prioritize upgrading to version 1.12.4 as part of routine patch management but may deprioritize this relative to higher-severity vulnerabilities.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.12.4CPE matchmatch criteria
cpe:2.3:a:monetr:monetr:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.2HIGH

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.45%
Probability of exploitation in next 30 days
EPSS Percentile
36.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0045 is in the 15th percentile among its peer group of 51,466 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (2)

gopatch availablevia ghsa
Product: github.com/monetr/monetrFixed in: 1.12.4
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

goGHSA-v7xq-3wx6-fqc2high

In monetr, unauthenticated Stripe webhook reads attacker-sized request bodies before signature validation

Apr 14, 2026

References

github.com / monetr/monetr/releases/tag/v1.12.4
Product
github.com / monetr/monetr/security/advisories/GHSA-v7xq-3wx6-fqc2
ExploitVendor Advisory