Description
It is possible to make the entire Cube API unavailable by submitting a specially crafted request to a Cube API endpoint.
Recommendation
Update the @cubejs-backend/server-core package to the latest compatible version. Followings are version details:
Affected version(s): **>= 1.5.0, < 1.5.13 >= 1.1.17, < 1.4.2** Patched version(s): **1.5.13 1.4.2**
References
Could your website be exposed too?
SmartScanner can check your website for Cube Core is vulnerable to Denial of Service (DoS) via crafted request and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Cube Core is vulnerable to privilege escalation via a specially crafted request - CVE-2026-25958
- jsPDF Vulnerable to Denial of Service (DoS) via Unvalidated BMP Dimensions in BMPDecoder - CVE-2026-24133
- ExifReader is vulnerable to denial of service via crafted ICC `mluc` tag - CVE-2026-8813
- path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters - CVE-2026-4867
You might also like:
See something that needs correcting? Let us knowUpdated February 10, 2026


