CVE-2026-50878: Feuerhamster MailForm v1.1.0 Denial of Service Vulnerability
Feuerhamster MailForm version 1.1.0 contains a vulnerability in how it handles file attachments. An attacker can send a specially crafted request to the application that causes it to become unresponsive or crash, denying legitimate users access to the service. No authentication is required to trigger this issue, and it can be exploited over the network.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.5 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Weaknesses (CWE)
- CWE-400
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-15 / 2026-06-17
NVD description (verbatim)
An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted request.
2 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-50878 is a Denial of Service vulnerability affecting Feuerhamster MailForm v1.1.0's attachment handling component. The flaw is rooted in improper resource management (CWE-400: Uncontrolled Resource Consumption), allowing unauthenticated network-based attackers to exhaust application resources via a crafted request. The vulnerability requires no user interaction and impacts service availability without affecting confidentiality or integrity. CVSS 3.1 score of 7.5 reflects the HIGH severity classification.
Business impact
Organizations running Feuerhamster MailForm v1.1.0 face potential service disruptions. An attacker can render the mail form application unavailable to end-users, disrupting email submission workflows and affecting any dependent business processes. Since exploitation does not require authentication or special access, the attack surface is broad. The absence of this vulnerability from CISA's Known Exploited Vulnerabilities (KEV) catalog as of the vulnerability publication date does not diminish the operational risk posed by unpatched instances.
Affected systems
Feuerhamster MailForm version 1.1.0 is explicitly affected. Organizations should audit their deployments to identify instances running this version. If vendor information on affected version ranges or compatibility of patches with other versions becomes available, cross-reference against your inventory.
Exploitability
The vulnerability is relatively straightforward to exploit. It requires only network access and a crafted HTTP request—no authentication, no user interaction, and no complex attack chains. The low attack complexity and absence of privilege requirements mean that opportunistic attackers, as well as targeted threat actors, can readily attempt exploitation. However, no public exploit code is known to exist in widely-used repositories at the time of advisory publication.
Remediation
Upgrade Feuerhamster MailForm to a patched version beyond v1.1.0. Consult the vendor's security advisories to identify the correct target version for your deployment. If an immediate patch is unavailable, temporarily restrict network access to the mail form application via firewall rules, rate limiting, or IP allowlisting to reduce exposure while a patch is prepared or procured.
Patch guidance
Contact Feuerhamster or check their official security advisories for patch availability and installation procedures for v1.1.0. Verify compatibility with any dependent systems or plugins before deploying patches to production. Plan a timely update given the HIGH severity and ease of exploitation. Test patches in a non-production environment first to ensure no functional regressions.
Detection guidance
Monitor for unusual request patterns targeting the mail form's attachment handling endpoints, such as repeated requests with malformed or oversized payloads. Watch for application crashes, restarts, or elevated CPU/memory consumption correlated with specific request signatures. Intrusion detection systems should flag requests designed to exhaust resources. Review application logs for errors or warnings originating from the attachment processing component. If applicable, enable verbose logging on the attachment handler during investigation.
Why prioritize this
This vulnerability merits rapid patching because of its HIGH CVSS severity, ease of exploitation (network-accessible, no authentication), and direct impact on service availability. The lack of KEV listing does not reduce urgency; the vulnerability is trivial to exploit and could enable competitors, extortionists, or other adversaries to disrupt your email intake mechanisms.
Risk score, explained
The CVSS 3.1 score of 7.5 (HIGH) reflects a network-exploitable vulnerability with low attack complexity, requiring no privileges or user interaction, that significantly impacts availability. Although confidentiality and integrity are not affected, the uncontrolled resource consumption allows a remote attacker to fully degrade or disable the service, resulting in the highest impact rating for availability (High).
Frequently asked questions
Is Feuerhamster MailForm v1.0.x or earlier affected?
The advisory explicitly references v1.1.0. No other versions are mentioned in the source data. Contact your vendor or check their security advisories to determine if earlier or later versions are also vulnerable.
Can this vulnerability be exploited without network access?
No. The CVSS vector indicates the attack vector is Network (AV:N), meaning the vulnerability is exploitable remotely over the network without requiring local system access.
Will a Web Application Firewall (WAF) help mitigate this?
A WAF may help by rate-limiting or blocking suspicious attachment-related requests, but it is not a substitute for patching. A properly configured WAF can delay or prevent some exploitation attempts while patches are being rolled out.
Why is this vulnerability not on CISA's KEV list?
CISA's KEV catalog tracks vulnerabilities with active, in-the-wild exploitation confirmed by government or security research. This vulnerability's absence from that list does not mean it is safe; it indicates no confirmed widespread exploitation as of publication, but that can change.
This analysis is based on official CVE and CVSS data published as of the vulnerability modification date (2026-06-17). Patch availability, exploitation in the wild, and vendor statements may evolve after publication. Validate all technical details and version numbers directly against vendor advisories before making remediation decisions. SEC.co does not provide legal, compliance, or procurement advice; consult your organization's security and legal teams regarding required remediation timelines. Source: NVD (public-domain), retrieved 2026-07-24. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2024-14036HIGHDräger Core Denial of Service via Malformed SDC Messages
- CVE-2025-52293HIGHGPAC MP4Box HEVC Parser Denial of Service (CVSS 7.5)
- CVE-2026-10069HIGHShibby Tomato miniupnpd Resource Exhaustion Vulnerability
- CVE-2026-10143HIGHkafka-python SCRAM DoS – Event Loop Freeze Vulnerability
- CVE-2026-34713HIGHAdobe CAI Content Credentials Denial-of-Service Vulnerability
- CVE-2026-35266HIGHOracle REST Data Services Authentication & Data Integrity Vulnerability
- CVE-2026-35277HIGHOracle REST Data Services Authorization Bypass
- CVE-2026-37234HIGHFlexRIC E42 Resource Leak via Multiple xapp_id Binding