Home

Description

An uncontrolled allocation of resources without limits or throttling in the e-mail handling in OTRS allows excessive allocation which may lead to the abortion of the webserver.This issue affects OTRS: * 8.0.X * 2023.X * 2024.X * 2025.X * 2026.X before 2026.4.X Please note that ((OTRS)) Community Edition 6.x, OTRS 7.x and products based on the ((OTRS)) Community Edition also very likely to be affected

PUBLISHED Reserved 2026-05-21 | Published 2026-06-01 | Updated 2026-06-01 | Assigner OTRS




MEDIUM: 5.7CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H

Problem types

CWE-400 Uncontrolled Resource Consumption

CWE-770 Allocation of Resources Without Limits or Throttling

Product status

Default status
unknown

7.0.x
unknown

8.0.x
affected

2023.x
affected

2024.x
affected

2025.x
affected

2026.x (patch)
affected

Default status
unknown

6.x
unknown

References

otrs.com/release-notes/otrs-security-advisory-2026-06/

cve.org (CVE-2026-48187)

nvd.nist.gov (CVE-2026-48187)

Download JSON