SCA: security update for github.com/jhaals/yopass (GHSA-6r69-c6wg-7g8m)

high Tenable Self-Hosted Container Security Plugin ID 474081

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- yopass is a service for securely sharing secrets, passwords, and files. Prior to version 14.7.0, the
Prometheus metrics middleware in pkg/server/server.go uses the attacker-controlled r.Method value directly
as the method label for yopass_http_requests_total and yopass_http_request_duration_seconds. Because the
catch-all route accepts arbitrary HTTP method tokens, an unauthenticated remote attacker can submit many
unique methods and create metric series that the Prometheus registry never evicts. The resulting monotonic
memory growth can OOM-kill the process, while the expanding registry also degrades /metrics scrape latency
and can blind monitoring. This issue is fixed in version 14.7.0. (CVE-2026-107840)

Solution

Update the github.com/jhaals/yopass library and its related packages to version 0.0.0-20260727191436-61e31ead04a4 or later.

See Also

https://github.com/advisories/GHSA-6r69-c6wg-7g8m

Plugin Details

Severity: High

ID: 474081

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 10/10/2026

Updated: 10/10/2026

Risk Information

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-107840

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/9/2026

Vulnerability Publication Date: 10/9/2026

Reference Information

CVE: CVE-2026-107840

cwe: CWE-400