Allocation of Resources Without Limits or Throttling in n8n - #VU153002
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the OAuth authorization endpoint when resolving OAuth clients from URL paths. A remote attacker can send authorization requests with identifiers that differ only by query strings to cause a denial of service.
The persisted records are marked as first-party and outlive the resources they name.