Cube Semantic Layer Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in Cube, a semantic layer for building data applications. This issue affects versions 1.1.17 prior to 1.5.13, as well as 1.4.2. An authenticated attacker can make the entire Cube API unavailable by sending a specially crafted request to an API endpoint.

Impact

Exploitation of this vulnerability leads to a crash of the server, making the Cube API unavailable.

Remediation

Users can upgrade to version 1.5.13 or 1.4.2 to address this vulnerability.

Added: Feb 10, 2026, 2:19 AM
Updated: Feb 10, 2026, 2:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
0.0
relevance
2.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.