PT-2026-46239 · Solarwinds · Serv-U
CVE-2026-28318
·
Published
2026-06-03
·
Updated
2026-07-03
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
SolarWinds Serv-U versions prior to 15.5.4 Hotfix 1
Description
SolarWinds Serv-U is susceptible to uncontrolled resource consumption when processing compressed HTTP request bodies. An unauthenticated remote attacker can trigger a denial-of-service condition, causing the service to crash, by sending a specially crafted POST request to the web interface. The attack utilizes a decompression bomb via the
Content-Encoding header set to deflate, which forces the system to exhaust CPU and memory resources during decompression before authentication occurs.There are over 12,000 instances of Serv-U exposed to the internet. This issue has been confirmed as actively exploited in the wild.
Recommendations
Update to SolarWinds Serv-U 15.5.4 Hotfix 1.
Restrict access to the Serv-U web interface to trusted IP addresses.
Block all requests containing the
Content-Encoding header, as the software does not utilize this functionality.
Monitor web and application logs for anomalous POST requests and sudden spikes in CPU or RAM usage by the Serv-U process.Fix
RCE
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Serv-U