Skip to content

Unbounded, uncancellable CUE evaluation enables denial of service

High
migmartri published GHSA-vm9j-jr3m-xmvm Aug 25, 2026

Package

gomod github.com/chainloop-dev/chainloop (Go)

Affected versions

< 1.103.0

Patched versions

1.103.0

Description

Impact

A roughly 55-byte workflow contract in CUE format could consume unbounded memory and CPU with no time or evaluation budget, taking down a shared control-plane container and every tenant on it. It is reachable by the lowest-privilege role, since any signup owns an organization.

Chainloop accepted workflow contracts in JSON, YAML or CUE. CUE is a Turing-rich configuration language with comprehensions and a standard library; it was compiled with no size, time or evaluation budget, and with no context.Context on the evaluation path.

A constant payload, in which only N varies:

import "list"
a: [for x in list.Range(0,N,1) {x}]

At N = 200k this burns roughly 500 MB and 34 seconds. At N = 1M it does not return, with memory still climbing past 685 MB when cut off. Because no context is threaded through the evaluation path, the server's 10-second request timeout returns an error to the client while the evaluation goroutine keeps running — the work cannot be reclaimed, and it accumulates across requests. A handful of small fire-and-forget requests is enough to exhaust and OOM-kill a shared control-plane container, taking down every tenant on that instance.

Payload size limits do not help against a 55-byte bomb. The properties that matter are boundedness and cancellability, and a general-purpose configuration language does not guarantee either.

Anyone running the Control Plane on a version before 1.103.0 is affected.

Patches

Fixed in v1.103.0, which removes CUE support entirely. Upgrade the Control Plane to v1.103.0 or later.

CUE was a rarely used and never fully supported third contract format behind JSON and YAML. That is why the fix removes it outright rather than bounding the evaluator: no supported workflow depended on it. JSON and YAML contracts are unaffected, so for nearly all users the upgrade requires no change. The stored format value is retained as inert, so contracts already saved as CUE and the existing API remain valid, and no database migration is required.

Chainloop's hosted service (chainloop.dev) is already patched.

Workarounds

None. There is no configuration toggle to refuse CUE contracts before v1.103.0, and payload size limits are not effective against this. Upgrading is required.

References

Severity

High

CVSS overall score

This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS).
/ 10

CVSS v3 base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
High

CVSS v3 base metrics

Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability.
Attack complexity: More severe for the least complex attacks.
Privileges required: More severe if no privileges are required.
User interaction: More severe when no user interaction is required.
Scope: More severe when a scope change occurs, e.g. one vulnerable component impacts resources in components beyond its security scope.
Confidentiality: More severe when loss of data confidentiality is highest, measuring the level of data access available to an unauthorized user.
Integrity: More severe when loss of data integrity is the highest, measuring the consequence of data modification possible by an unauthorized user.
Availability: More severe when the loss of impacted component availability is highest.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

CVE ID

No known CVE

Weaknesses

Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource. Learn more on MITRE.