Sourcecodester · Customer Review App · CVE-2026-10295
**Name of the Vulnerable Software and Affected Versions**
SourceCodester Customer Review App version 1.0
**Description**
A denial of service can be triggered through the manipulation of the `name` and `comment` arguments. This issue affects the `add review()`, `save review()`, and `get all reviews()` functions within the `review app.py` file. The attack requires a local approach.
**Recommendations**
Update SourceCodester Customer Review App version 1.0 to a patched version.
As a temporary workaround, restrict access to the `add review()`, `save review()`, and `get all reviews()` functions in the `review app.py` file.