F-MOBY-001-001: Access control. An oversized request body bypasses the authorization plugin decision. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
pkg/authz: Reject requests exceeding body size limit
fixed publicly
details
Finding IDs
F-MOBY-001-001
Status
fixed publicly
Reported via
security contact
Note
public fix commit 7a767b27fd12 appears to address the reported issue. GHSA-x744-4wpc-v9h2 / CVE-2026-34040 published with credit to 1seal / Oleh Konko.
F-MOBY-001-001: Access control. An oversized request body bypasses the authorization plugin decision. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.