GSSA-2026-04-3ZVC5D2026-04-256.5 Medium
Unbounded pagination limits enable resource exhaustion in cobc-events
Several REST endpoints accepted a client-controlled `limit` query parameter with no upper bound, allowing authenticated users to request arbitrarily large result sets and exhaust database / memory.
Several REST endpoints accepted a client-controlled limit query parameter with no upper bound, allowing authenticated users to request arbitrarily large result sets and exhaust database / memory.