Synchronous Access of Remote Resource without Timeout in draw.io - #VU147248
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to synchronous access to a remote resource without a timeout in ExportProxyServlet when handling concurrent requests to the /service/* endpoint while the configured EXPORT_URL backend is unresponsive. A remote attacker can send concurrent requests to exhaust the servlet thread pool to cause a denial of service.