Allocation of Resources Without Limits or Throttling in n8n - CVE-2026-42236
Published: April 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource control in the MCP OAuth client registration endpoint when handling unauthenticated client registration requests. A remote attacker can send large registration payloads to cause a denial of service.
The endpoint is reachable regardless of whether MCP access is enabled on the instance.