PT-2026-24055 · Owasp · Owasp Defectdojo

H3Nrrrych4U

·

Published

2026-03-09

·

Updated

2026-03-09

·

CVE-2026-3816

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OWASP DefectDojo versions through 2.55.4
Description A security issue has been identified in OWASP DefectDojo related to denial of service. The issue resides in the input zip.read function within the parser.py file of the SonarQubeParser/MSDefenderParser component. This allows for remote exploitation, and the exploit has been publicly disclosed.
Recommendations Upgrade to version 2.56.0 or later.

Exploit

Fix

DoS

Improper Resource Release

Weakness Enumeration

Related Identifiers

CVE-2026-3816

Affected Products

Owasp Defectdojo