CVE-2026-4249

HIGHCVSS 8.6/10EPSS 0.34%

Last modified

CVE-2026-4249 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an unauthenticated remote attacker to inject malicious JSON data that can lead to a persistent denial of service condition. Successful exploitation of this vulnerability can disrupt the API Gateway, preventing legitimate API traffic from being processed and impacting complete service availability. EPSS estimates a 0.34% chance of exploitation in the next 30 days.

Description

The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an unauthenticated remote attacker to inject malicious JSON data that can lead to a persistent denial of service condition. Successful exploitation of this vulnerability can disrupt the API Gateway, preventing legitimate API traffic from being processed and impacting complete service availability. The denial of service is persistent, requiring manual intervention to restore normal operations.

Metrics

CVSS 3.1
8.6/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

EPSS Probability
0.34%

25.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Wso2Api Control Plane>= 4.5.0, < 4.5.0.55
Wso2Api Control Plane>= 4.6.0, < 4.6.0.19
Wso2Api Manager>= 4.0.0, < 4.0.0.390
Wso2Api Manager>= 4.1.0, < 4.1.0.254
Wso2Api Manager>= 4.2.0, < 4.2.0.194
Wso2Api Manager>= 4.3.0, < 4.3.0.105
Wso2Api Manager>= 4.4.0, < 4.4.0.69
Wso2Api Manager>= 4.5.0, < 4.5.0.54
Wso2Api Manager>= 4.6.0, < 4.6.0.18
Wso2Traffic Manager>= 4.5.0, < 4.5.0.53
Wso2Traffic Manager>= 4.6.0, < 4.6.0.18
Wso2Universal Gateway>= 4.5.0, < 4.5.0.54
Wso2Universal Gateway>= 4.6.0, < 4.6.0.18

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2026-4249?
The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an unauthenticated remote attacker to inject malicious JSON data that can lead to a persistent denial of service condition. Successful exploitation of this vulnerability can disrupt the API Gateway, preventing legitimate API traffic from being processed and impacting complete service availability. The denial of service is persistent, requiring manual intervention to restore normal operations.
How severe is CVE-2026-4249?
CVE-2026-4249 has a CVSS score of 8.6/10 (HIGH severity). The EPSS model estimates a 0.34% probability of exploitation in the next 30 days.
How do I fix CVE-2026-4249?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-4249?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST