CVE-2026-33241Disclosure(salvo / salvo)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch salvo salvo systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Salvo is a Rust web framework. Prior to version 0.89.3, Salvo's form data parsing implementations (`form_data()` method and `Extractible` macro) do not enforce payload size limits before reading request bodies into memory. This allows attackers to cause Out-of-Memory (OOM) conditions by sending extremely large payloads, leading to service crashes and denial of service. Version 0.89.3 contains a patch.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • salvo

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-24); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
salvo

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-24: 3Mentions · 2026-03-26: 1Patch / Workaround · 2026-03-24: 2Technical Details · 2026-03-24: 2Technical Details · 2026-03-26: 103-2403-26
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-243
Disclosure2Patch1
2026-03-261
Disclosure1
Full discourse4 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    A DoS vulnerability (CVE-2026-33241) affects `Salvo` via unbounded memory allocation during form data parsing. This can lead to service unavailability. Monitor for vendor updates. #DoS #MemoryAllocation #infosec https://www.pulsepatch.io/posts/cve-2026-33241-salvo-denial-of-service

    Post summary

    CVE‑2026‑33241 is a DoS flaw in Salvo due to unbounded memory allocation during form parsing; the post provides technical details but no PoC, exploit code, or active exploitation reports, and simply encourages monitoring vendor updates.

    0000043
    3 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-33241 📊 Severity: 8.7 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33241 #CVE-2026-33241 #CVE #High #CyberSecurity #InfoSec https://t.co/12UlnsxPVC

    Post summary

    A new CVE—CVE‑2026‑33241—has been announced with a severity score of 8.7, affecting unspecified products, but no additional details or exploit information are provided.

    0000024
    111 followersView on X
  • Fernando Karl@fernandokarl
    Patch

    🚨 Atenção desenvolvedores que usam o framework Rust Salvo! Uma vulnerabilidade de DoS por OOM foi corrigida na v0.89.3. Atualize agora para evitar requisições excessivas que podem derrubar seu serviço! 🛠️ 🔗 Saiba mais: https://www.tenable.com/cve/CVE-2026-33241 #CyberSecurity #Rust #DevSecOps

    Post summary

    The post alerts developers that a DoS‑by‑OOM vulnerability in Rust Salvo has been fixed in v0.89.3 and urges an update, without reporting exploitation or a PoC.

    0000036
    258 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33241 Salvo is a Rust web framework. Prior to version 0.89.3, Salvo's form data parsing implementations (`form_data()` method and `Extractible` macro) do not enforce payloa… https://www.cve.org/CVERecord?id=CVE-2026-33241

    Post summary

    CVE-2026-33241 exposes a flaw in Salvo’s form data parsing that may allow incorrect payload handling, fixed in version 0.89.3, with no evidence of exploitation or PoC provided.

    00000147
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsalvosalvo-rust-

Explore more