
🚨High - WSO2 API Gateway Persistent Denial of Service (CVE-2026-4249) The throttling event handler across multiple WSO2 products accepts user-supplied JSON without validating its structure or content. An unauthenticated, remote attacker can send a crafted JSON payload that crashes the API Gateway — with no authentication and no user interaction required. The resulting denial of service is persistent: legitimate API traffic stops flowing and the gateway requires manual intervention to recover, taking down every service behind that choke point until an operator steps in. 👉Affected: WSO2 API Manager 3.2.0–4.7.0, Universal Gateway, Traffic Manager & API Control Plane — see advisory WSO2-2026-5236 for fixed patch levels.
Post summary
WSO2 disclosed a high‑severity persistent DoS (CVE‑2026‑4249) caused by unsanitized JSON handling, with an advisory providing patched versions; no PoC, exploit code, or active exploitation is referenced.
