SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84856

MEDIUM · CVSS 5.3 EPSS 0.40% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability in the Composio Webhook Endpoint of Rowboat Labs' application allows for remote denial of service attacks due to improper handling of request data in the affected version up to 0.9.1. Organizations using this component should prioritize upgrading to version 0.9.2, as the previous version has been deprecated without any security controls in place. Given the public availability of the exploit, immediate action is recommended to mitigate potential disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-84856
Severity
MEDIUM
CVSS
5.3
EPSS
0.40%

Original NVD Description

A vulnerability was detected in rowboatlabs rowboat up to 0.9.1. The impacted element is the function request.text/req.json of the file apps/rowboat/app/api/composio/webhook/route.ts of the component Composio Webhook Endpoint. The manipulation results in denial of service. It is possible to launch the attack remotely. The exploit is now public and may be used. Upgrading to version 0.9.2 is sufficient to resolve this issue. Upgrading the affected component is recommended. The legacy Next.js app was deleted at 0.9.2 rather than patched, leaving no security control behind.