CVE-2026-40481 is a denial of service vulnerability in monetr, a budgeting application, affecting versions 1.12.3 and below. The flaw exists in the public Stripe webhook endpoint, which fails to validate webhook signatures before buffering request bodies into memory. An unauthenticated remote attacker can exploit this by sending oversized POST payloads to cause uncontrolled memory consumption and application unavailability. The vulnerability only impacts deployments with Stripe webhooks enabled and can be mitigated through upstream proxy request size limits until patching to version 1.12.4 is available. The attack vector is network-based and requires minimal complexity, as an attacker simply needs to send crafted HTTP requests without authentication. While the CVSS score is not provided, the FAUCET Risk Score of 40.0/100 and EPSS of 0.00185 indicate low to moderate severity with limited widespread risk. The primary impact is availability, through denial of service caused by memory exhaustion, rather than confidentiality or integrity compromise. There is no evidence of active exploitation, as the vulnerability is not listed in the Known Exploited Vulnerabilities catalog and remains on the inactive Hot List. The low EPSS score suggests minimal community attention or exploit development. Organizations should prioritize upgrading to version 1.12.4 as part of routine patch management but may deprioritize this relative to higher-severity vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.12.4CPE matchmatch criteria | cpe:2.3:a:monetr:monetr:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.