Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-55241— Checkmate: Pre-auth Denial of Service via File Upload on Registration

Quick assessment

Affected
bluewave-labs Checkmate
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Checkmate 是一款开源、可自托管的工具,旨在通过美观的可视化界面,实时跟踪和监控服务器硬件状态、运行时间、响应时间以及事件情况。在版本 3.9.1 之前,位于 中的公开 POST 路由在注册验证之前,会通过位于 的基于内存的 Multer 解析机制处理多部分表单中的 上传请求,且该上传中间件未设置文件大小、文件数量或 MIME 类型限制。未认证的攻击者可以提交并发的大尺寸文件,这些文件会在无效注册或邀请令牌检查拒绝请求之前被缓冲到内存中,从而耗尽服务器内存,导致后端崩溃或不稳定。该问题已在版本 3.9.1

CVSS 7.5 · High EPSS 0.44% · P36

Affected Version Matrix 1

VendorProduct Version RangeStatus
bluewave-labs Checkmate < 3.9.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-55241

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Checkmate: Pre-auth Denial of Service via File Upload on Registration
Source: CVE Program / CVE List V5
Vulnerability Description
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. Prior to 3.9.1, the public POST /api/v1/auth/register route in server/src/api/routes/authRoutes.ts passes multipart profileImage uploads through in-memory Multer parsing before registration validation, without file-size, file-count, or MIME-type limits in server/src/api/middleware/upload.ts. An unauthenticated attacker can submit concurrent oversized files that are buffered before invalid registration or invite-token checks reject the request, exhausting memory and crashing or destabilizing the backend. This issue is fixed in version 3.9.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
bluewave-labs Checkmate < 3.9.1 -

II. Public POCs for CVE-2026-55241

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 7234 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-55241

登录查看更多情报信息。

Patches & Fixes for CVE-2026-55241 (1)

Vendor Advisories for CVE-2026-55241 (1)

Other References for CVE-2026-55241 (1)

Same Patch Batch · bluewave-labs · 2026-08-21 · 3 CVEs total

CVE-2026-71862 7.5 HIGH Checkmate: Sensitive Bearer Token Exposure via Public Status Pages When showURL Setting is
CVE-2026-70656 4.9 MEDIUM Checkmate: Regular Expression Denial of Service (ReDoS) via User-Controlled Regex in Monit

IV. Related Vulnerabilities

V. Comments for CVE-2026-55241

No comments yet


Leave a comment