Skip to main content
HIGH

CVE-2026-107840

CVSS v3

7.5

HIGH

EPSS Score

—

exploit probability

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

yopass is a service for securely sharing secrets, passwords, and files. Prior to version 14.7.0, the Prometheus metrics middleware in pkg/server/server.go uses the attacker-controlled r.Method value directly as the method label for yopass_http_requests_total and yopass_http_request_duration_seconds. Because the catch-all route accepts arbitrary HTTP method tokens, an unauthenticated remote attacker can submit many unique methods and create metric series that the Prometheus registry never evicts.

Technical details

CVSS v3 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Published
2026-10-09
Last Modified
2026-10-09

Frequently asked questions

What is CVE-2026-107840?

yopass is a service for securely sharing secrets, passwords, and files. Prior to version 14.7.0, the Prometheus metrics middleware in pkg/server/server.go uses the attacker-controlled r.Method value directly as the method label for yopass_http_requests_total and yopass_http_request_duration_seconds. Because the catch-all route accepts arbitrary HTTP method tokens, an unauthenticated remote attacker can submit many unique methods and create metric series that the Prometheus registry never evicts.

Is CVE-2026-107840 actively exploited?

Active exploitation of CVE-2026-107840 has not been confirmed.

What is the CVSS score for CVE-2026-107840?

CVE-2026-107840 has a CVSS v3 base score of 7.5 (HIGH severity), with vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.

Is CVE-2026-107840 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 50 free checks/month · Free API key