Resource exhaustion in snipe-it - #VU145073
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in the POST /account/accept/{acceptance} endpoint when rendering an unbounded note field synchronously through the CommonMark mail markdown pipeline. A remote user can submit a specially crafted oversized note to cause a denial of service.
The issue affects default installations using the synchronous queue driver, and exploitation requires an assigned pending checkout acceptance.