GHSA-pr9r-gxgp-9rm8
n8n Vulnerable to Denial of Service via Malformed Binary Data Requests
상세
## Summary Denial of Service vulnerability in `/rest/binary-data` endpoint when processing empty filesystem URIs (`filesystem://` or `filesystem-v2://`).
### Impact This is a Denial of Service (DoS) vulnerability that allows authenticated attackers to cause service unavailability through malformed filesystem URI requests. The vulnerability affects:
- The `/rest/binary-data` endpoint - n8n.cloud instances (confirmed HTTP/2 524 timeout responses)
Attackers can exploit this by sending GET requests with empty filesystem URIs (`filesystem://` or `filesystem-v2://`) to the `/rest/binary-data` endpoint, causing resource exhaustion and service disruption.
### Patches
The issue has been patched in [1.99.0](https://github.com/n8n-io/n8n/releases/tag/n8n%401.99.0). All users should upgrade to this version or later.
The fix introduces strict checking of URI patterns.
Patch commit: https://github.com/n8n-io/n8n/pull/16229
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
참고
- https://github.com/n8n-io/n8n/security/advisories/GHSA-pr9r-gxgp-9rm8 [WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-49595 [ADVISORY]
- https://github.com/n8n-io/n8n/pull/16229 [WEB]
- https://github.com/n8n-io/n8n/commit/43c52a8b4f844e91b02e3cc9df92826a2d7b6052 [WEB]
- https://github.com/n8n-io/n8n [PACKAGE]