#VU122472 Resource exhaustion in n8n - CVE-2025-49595
Published: February 9, 2026
n8n
n8n
Description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources "/rest/binary-data" endpoint when processing empty filesystem URIs (filesystem:// or filesystem-v2://). A remote privileged user can trigger resource exhaustion and perform a denial of service (DoS) attack.