Cube Semantic Layer Denial-of-Service Vulnerability
Vulnerability
A denial-of-service vulnerability has been identified in Cube, a semantic layer for building data applications. This issue affects versions 1.1.17 prior to 1.5.13, as well as 1.4.2. An authenticated attacker can make the entire Cube API unavailable by sending a specially crafted request to an API endpoint.
Impact
Exploitation of this vulnerability leads to a crash of the server, making the Cube API unavailable.
Remediation
Users can upgrade to version 1.5.13 or 1.4.2 to address this vulnerability.
Added: Feb 10, 2026, 2:19 AM
Updated: Feb 10, 2026, 2:19 AM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
2.5exploitability
5.2remediation
0.0relevance
2.6threat
0.0urgency
2.9incentive
0.0Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
