PT-2026-34840 · Unknown · Ossn Open Source Social Network
Published
2026-04-24
·
Updated
2026-04-25
·
CVE-2026-41309
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Open Source Social Network versions prior to 9.0
Description
Resource exhaustion occurs when an attacker uploads a specially crafted image with extreme pixel dimensions. Although the compressed file size may be small, the server allocates excessive memory and CPU cycles during decompression and resizing, resulting in a Denial of Service (DoS) condition, which is a state where a system becomes unavailable to its intended users.
Recommendations
Update to version 9.0.
Adjust
php.ini settings to strictly limit memory limit and max execution time.
Implement client-side and server-side checks on image headers to reject files exceeding reasonable pixel dimensions before processing.Fix
Resource Exhaustion
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ossn Open Source Social Network