A NULL pointer dereference vulnerability in fastschema through v0.15.1 allows an unauthenticated remote attacker to crash the server process with a single HTTP request. The sendOTPEmail function in pkg/auth/local.go dereferences a pointer obtained from an unchecked error path without validating it is non-nil, causing a fatal panic that terminates the entire server when a recovery request is sent to the /api/auth/local/recover endpoint.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fastschema
Fastschema fastschema |
|
| Vendors & Products |
Fastschema
Fastschema fastschema |
Mon, 10 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Aug 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A NULL pointer dereference vulnerability in fastschema through v0.15.1 allows an unauthenticated remote attacker to crash the server process with a single HTTP request. The sendOTPEmail function in pkg/auth/local.go dereferences a pointer obtained from an unchecked error path without validating it is non-nil, causing a fatal panic that terminates the entire server when a recovery request is sent to the /api/auth/local/recover endpoint. | |
| Title | fastschema - Unauthenticated NULL Pointer Dereference DoS in Account Recovery Endpoint | |
| Weaknesses | CWE-476 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: TuranSec
Published: 2026-08-10T10:41:21.786Z
Updated: 2026-08-10T13:17:44.659Z
Reserved: 2026-08-10T10:32:53.854Z
Link: CVE-2026-72582
Updated: 2026-08-10T13:17:40.786Z
Status : Received
Published: 2026-08-10T11:17:31.137
Modified: 2026-08-10T14:17:29.123
Link: CVE-2026-72582
No data.