NVD Vulnerability Detail
Search Exploit, PoC
CVE-2026-9137
Summary

The CSP report endpoint intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted clients, this could allow attackers to generate excessive log volume and contribute to resource exhaustion or log flooding.

Publication Date May 21, 2026, 5:16 a.m.
Registration Date May 22, 2026, 4:07 a.m.
Last Update May 22, 2026, 1:04 a.m.
Related information, measures and tools
Common Vulnerabilities List