ISC Stork Unauthenticated Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in ISC Stork versions 1.0.0 prior to 2.3.0. The issue arises when an unauthenticated user sends a large volume of data to the Stork UI, potentially leading to memory and disk usage problems on the server running Stork.

Impact

Exploitation of this vulnerability causes resource exhaustion, where excessive input leads Stork to use more memory than available. This can cause the 'stork-server' process, or other processes, to fail. Additionally, smaller inputs may not fully exhaust memory but can fill log storage or trigger premature log rotation.

Remediation

Users can upgrade to Stork versions 2.2.1 or 2.3.1 to address this vulnerability.

Added: Sep 10, 2025, 6:17 PM
Updated: Sep 10, 2025, 6:17 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
2.5
exploitability
7.0
remediation
7.9
relevance
0.5
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.