
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4249 is a JSON injection vulnerability in the throttling event handling mechanism of multiple WSO2 products that allows unauthenticated remote attackers to cause a persistent denial of service condition. Disclosed on July 6, 2026, it affects WSO2 API Manager (versions 3.2.0 through 4.7.0 across multiple patch branches), WSO2 API Control Plane (4.5.0–4.7.0), WSO2 Universal Gateway (4.5.0–4.7.0), and WSO2 Traffic Manager (4.5.0–4.7.0). The vulnerability carries a CVSS v3.1 base score of 8.6 (High) with a changed scope, reflecting its potential to impact components beyond the directly vulnerable service (GitHub Advisory, WSO2 Advisory).
The root cause is classified as CWE-707 (Improper Neutralization), where the throttling event handler in affected WSO2 products fails to adequately validate the structure and content of user-supplied JSON payloads before processing them. An unauthenticated remote attacker can craft and submit malicious JSON data to the throttling event handling endpoint over the network, with no privileges or user interaction required. The injected payload disrupts internal processing in a way that causes a persistent denial of service — meaning the service does not automatically recover and requires manual administrator intervention to restore normal operations (GitHub Advisory, WSO2 Advisory).
Successful exploitation disrupts the WSO2 API Gateway, preventing all legitimate API traffic from being processed and causing a complete loss of service availability. The denial of service is persistent — unlike transient DoS conditions, the affected system does not self-recover and requires manual intervention by an administrator to restore operations. There is no confidentiality or integrity impact reported; the vulnerability is limited to availability, but the scope change in the CVSS score indicates that components beyond the directly vulnerable service (such as downstream API consumers) are also affected (GitHub Advisory, WSO2 Advisory).
WSO2 has released patched versions addressing this vulnerability. Organizations should upgrade to the following fixed versions or later: WSO2 API Manager 3.2.0.470, 3.2.1.89, 4.0.0.390, 4.1.0.254, 4.2.0.194, 4.3.0.105, 4.4.0.69, 4.5.0.54, 4.6.0.18, or 4.7.0.2; WSO2 API Control Plane 4.5.0.55, 4.6.0.19, or 4.7.0.2; WSO2 Universal Gateway 4.5.0.54, 4.6.0.18, or 4.7.0.2; WSO2 Traffic Manager 4.5.0.53, 4.6.0.18, or 4.7.0.2. As interim mitigations, administrators should implement network-level rate limiting and input validation/sanitization for JSON payloads reaching the throttling event handler, and monitor for abnormal payload patterns. Applying the vendor patch is the recommended long-term solution (WSO2 Advisory, GitHub Advisory).
The vulnerability received routine coverage across CVE aggregation platforms and security community feeds shortly after disclosure on July 6, 2026. Social media activity was limited to automated CVE notification accounts on Bluesky and a Reddit daily brief post, with no notable independent researcher commentary or significant media coverage observed (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."