Input validation error in n8n - #VU134438
Published: June 12, 2026
n8n
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the Compression node Decompress operation when processing attacker-supplied ZIP archives through a public webhook workflow. A remote attacker can send a small crafted compressed archive to cause a denial of service.
The issue can exhaust memory and terminate the process, disrupting all workflows running in the same instance.