A flaw was found in search-v2-api. An unauthenticated...
High severity
Unreviewed
Published
Aug 13, 2026
to the GitHub Advisory Database
•
Updated Aug 13, 2026
Description
Published by the National Vulnerability Database
Aug 12, 2026
Published to the GitHub Advisory Database
Aug 13, 2026
Last updated
Aug 13, 2026
A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent entry in the unbounded tokenReviews cache, which is not properly cleared. This can lead to memory exhaustion of the search-api pod, resulting in a Denial of Service (DoS).
References