Improper Verification of Cryptographic Signature in Tolgee - #VU133251
Published: June 2, 2026
Tolgee
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper verification of cryptographic signature in SlackEventsController.validateAndParsePayload() and the /on-bot-event handler when processing crafted Slack bot-event payloads containing both a redirect value and an app_uninstalled event. A remote attacker can send a specially crafted request to cause a denial of service.
Successful exploitation requires knowledge or guessing of a connected Slack team_id and results in deletion of the corresponding Slack workspace integration, disabling Slack notifications and subscriptions until the workspace is reconnected.