Allocation of Resources Without Limits or Throttling Affecting php-fpm_exporter package, versions <2.2.0-r25


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.01% (4th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-WOLFILATEST-PHPFPMEXPORTER-16022387
  • published13 Apr 2026
  • disclosed8 Apr 2026

Introduced: 8 Apr 2026

NewCVE-2026-32283  (opens in a new tab)
CWE-770  (opens in a new tab)

How to fix?

Upgrade Wolfi php-fpm_exporter to version 2.2.0-r25 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream php-fpm_exporter package and not the php-fpm_exporter package as distributed by Wolfi. See How to fix? for Wolfi relevant fixed versions and status.

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

CVSS Base Scores

version 3.1