Improper Verification of Cryptographic Signature in Tolgee - #VU133251

 

Improper Verification of Cryptographic Signature in Tolgee - #VU133251

Published: June 2, 2026


Vulnerability identifier: #VU133251
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-347
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper verification of cryptographic signature in SlackEventsController.validateAndParsePayload() and the /on-bot-event handler when processing crafted Slack bot-event payloads containing both a redirect value and an app_uninstalled event. A remote attacker can send a specially crafted request to cause a denial of service.

Successful exploitation requires knowledge or guessing of a connected Slack team_id and results in deletion of the corresponding Slack workspace integration, disabling Slack notifications and subscriptions until the workspace is reconnected.


Affected software

Tolgee

Remediation

Install security update from vendor's website.

Tolgee - update to 3.194.0

External References

Related Security Bulletins