Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 27 Apr 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dayuanjiang next Ai Draw.io
|
|
| CPEs | cpe:2.3:a:dayuanjiang:next_ai_draw.io:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Dayuanjiang next Ai Draw.io
|
Wed, 22 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dayuanjiang
Dayuanjiang next-ai-draw-io |
|
| Vendors & Products |
Dayuanjiang
Dayuanjiang next-ai-draw-io |
Wed, 22 Apr 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Next AI Draw.io is a next.js web application that integrates AI capabilities with draw.io diagrams. Prior to 0.4.15, the embedded HTTP sidecar contains three POST handlers (/api/state, /api/restore, and /api/history-svg) that process incoming requests by accumulating the entire request body into a JavaScript string without any size limitations. Node.js buffers the entire payload in the V8 heap. Sending a sufficiently large body (e.g., 500 MiB or more) will exhaust the process heap memory, leading to an Out-of-Memory (OOM) error that crashes the MCP server. This vulnerability is fixed in 0.4.15. | |
| Title | Next AI Draw.io: Unbounded HTTP Body — Denial of Service | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-21T18:36:25.819Z
Reserved: 2026-04-14T14:07:59.642Z
Link: CVE-2026-40608
Updated: 2026-04-21T18:36:10.209Z
Status : Analyzed
Published: 2026-04-21T18:16:52.280
Modified: 2026-04-27T19:41:49.537
Link: CVE-2026-40608
No data.
OpenCVE Enrichment
Updated: 2026-04-22T11:45:56Z