CVE-2026-28318: CWE-400 Uncontrolled Resource Consumption in SolarWinds Serv-U
SolarWinds Serv-U contains a vulnerability where specially crafted POST requests using Content-Encoding: deflate can crash the Serv-U service without requiring authentication. This leads to a denial-of-service condition due to uncontrolled resource consumption. The vulnerability has a high severity rating with a CVSS score of 7.5. Mitigation guidance is available from SolarWinds Trust Center for customers unable to deploy updates. No specific affected versions or official patches have been disclosed yet.
AI Analysis
Technical Summary
CVE-2026-28318 is an uncontrolled resource consumption vulnerability (CWE-400) in SolarWinds Serv-U. It can be triggered by unauthenticated attackers sending specially crafted POST requests with Content-Encoding: deflate, causing the Serv-U service to crash. This results in a denial-of-service impact. The vulnerability is publicly known and assigned a CVSS 3.1 base score of 7.5, indicating high severity. No official remediation level or patch information is currently available. SolarWinds provides mitigation steps in their Trust Center for customers who cannot immediately update.
Potential Impact
The vulnerability allows unauthenticated attackers to cause a denial-of-service by crashing the Serv-U service through crafted POST requests. There is no confidentiality or integrity impact reported. The primary impact is service disruption.
Mitigation Recommendations
SolarWinds has published mitigation steps in their Trust Center for customers unable to deploy updates. Since no official patch or remediation level is currently confirmed, users should consult the SolarWinds Trust Center for recommended mitigations and apply them accordingly. Monitor vendor advisories for updates on patch availability.
CVE-2026-28318: CWE-400 Uncontrolled Resource Consumption in SolarWinds Serv-U
Description
SolarWinds Serv-U contains a vulnerability where specially crafted POST requests using Content-Encoding: deflate can crash the Serv-U service without requiring authentication. This leads to a denial-of-service condition due to uncontrolled resource consumption. The vulnerability has a high severity rating with a CVSS score of 7.5. Mitigation guidance is available from SolarWinds Trust Center for customers unable to deploy updates. No specific affected versions or official patches have been disclosed yet.
CVSS v3.1
Score 7.5high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-28318 is an uncontrolled resource consumption vulnerability (CWE-400) in SolarWinds Serv-U. It can be triggered by unauthenticated attackers sending specially crafted POST requests with Content-Encoding: deflate, causing the Serv-U service to crash. This results in a denial-of-service impact. The vulnerability is publicly known and assigned a CVSS 3.1 base score of 7.5, indicating high severity. No official remediation level or patch information is currently available. SolarWinds provides mitigation steps in their Trust Center for customers who cannot immediately update.
Potential Impact
The vulnerability allows unauthenticated attackers to cause a denial-of-service by crashing the Serv-U service through crafted POST requests. There is no confidentiality or integrity impact reported. The primary impact is service disruption.
Mitigation Recommendations
SolarWinds has published mitigation steps in their Trust Center for customers unable to deploy updates. Since no official patch or remediation level is currently confirmed, users should consult the SolarWinds Trust Center for recommended mitigations and apply them accordingly. Monitor vendor advisories for updates on patch availability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- SolarWinds
- Date Reserved
- 2026-02-26T14:46:41.520Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a218ccae29bf47b50ad1a7d
Added to database: 06/04/2026, 14:33:46 UTC
Last enriched: 06/12/2026, 10:17:21 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 85
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.