{"apiVersion":"1.0","identifier":"CVE-2026-63462","description":"Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the shared OpenAPI validation error path in src/lib/error/bad-data-error.ts passes a raw request value from lodash.get to JSON.stringify in genericErrorMessage and fromOpenApiValidationErrors without guarding stack exhaustion. An unauthenticated attacker can send a roughly 10 KB JSON value nested thousands of levels deep to POST /edge/validate, POST /edge/issue-token, or another OpenAPI-validated endpoint, causing RangeError: Maximum call stack size exceeded in openAPIValidationMiddleware and terminating the Node process because no uncaughtException handler recovers it. Replaying the request can sustain a complete service outage. This issue is fixed in versions 7.5.2, 7.6.5, and 8.0.2.","publishedAt":"2026-08-21T19:17:31","lastModifiedAt":"2026-08-25T18:17:58","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-63462","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","epssProbability":0.00379,"riskScore":0.78,"affectedProduct":"Unleash","affectedVersions":"<7.5.2, <7.6.5, <8.0.2","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-63462","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-63462","en":"https://www.redsauce.net/en/cves/CVE-2026-63462","fr":"https://www.redsauce.net/fr/cves/CVE-2026-63462","pt":"https://www.redsauce.net/pt/cves/CVE-2026-63462","de":"https://www.redsauce.net/de/cves/CVE-2026-63462","sk":"https://www.redsauce.net/sk/cves/CVE-2026-63462","el":"https://www.redsauce.net/el/cves/CVE-2026-63462"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-63462"}}