Medium [CVE-2026-49835] Denial of Service via unbounded metric label cardinality
This medium-severity Red Hat Linux advisory covers CVE-2026-49835.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps.
Prior to 2.1.0, the global wrapMetrics middleware records raw HTTP request path r.URL.Path and raw HTTP request method r.Method as Prometheus labels for latency and request count metric vectors before routing, allowing an unauthenticated remote attacker to issue requests with random paths such as /api/v1/timestamp/ or random HTTP methods and create unbounded permanent time-series entries that exhaust memory.
This issue is fixed in version 2.1.0. This leads to the creation of an excessive number of unique metric labels, causing unbounded memory growth and a denial of service (DoS) condition on the server.
This issue is a type of Improper Restriction of Resource Consumption (CWE-770). Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).
Weakness: CWE-770. Red Hat lists Red Hat Trusted Artifact Signer as not affected.
- < 2.1.0
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
Mitigation checklist
- Upgrade to timestamp-authority v2.0.7/v2.1.0 or later. As a workaround, block invalid methods and unknown paths at a reverse proxy.
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.