Skip to content
VulniPulse
Medium5.9Red Hat Linux

Medium [CVE-2026-49835] Denial of Service via unbounded metric label cardinality

This medium-severity Red Hat Linux advisory covers CVE-2026-49835.

CVE-2026-49835 Published Jun 30, 2026Updated by vendor Jun 30, 2026
Affected products & platforms
Red Hat LinuxUnclassified
Open vendor advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps.

Prior to 2.1.0, the global wrapMetrics middleware records raw HTTP request path r.URL.Path and raw HTTP request method r.Method as Prometheus labels for latency and request count metric vectors before routing, allowing an unauthenticated remote attacker to issue requests with random paths such as /api/v1/timestamp/ or random HTTP methods and create unbounded permanent time-series entries that exhaust memory.

This issue is fixed in version 2.1.0. This leads to the creation of an excessive number of unique metric labels, causing unbounded memory growth and a denial of service (DoS) condition on the server.

This issue is a type of Improper Restriction of Resource Consumption (CWE-770). Red Hat severity: Moderate — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).

Weakness: CWE-770. Red Hat lists Red Hat Trusted Artifact Signer as not affected.

Affected versions
  • < 2.1.0

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Fixed versions
  • 2.1.0

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Upgrade to timestamp-authority v2.0.7/v2.1.0 or later. As a workaround, block invalid methods and unknown paths at a reverse proxy.

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.