Review reviewHigh

CVE-2026-4249

WSO2 WSO2 Universal Gateway, WSO2 Traffic Manager, WSO2 API Control Plane

The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an unauthenticated remote attacker to inject malicious JSON data that can lead to a persistent denial of service condition. Successful exploitation of this vulnerability can disrupt the API Gateway, preventing legitimate API traffic from being processed and impacting complete service availability. The denial of service is persistent, requiring manual intervention to restore normal operations.

CVSS
8.6
EPSS
0.34%
26.5% percentile
CISA KEV
Not listed
Published
2026.07.06
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.34%
Technical severityCVSS 8.6

Vulnerability overview

The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an unauthenticated remote attacker to inject malicious JSON data that can lead to a persistent denial of service condition. Successful exploitation of this vulnerability can disrupt the API Gateway, preventing legitimate API traffic from being processed and impacting complete service availability. The denial of service is persistent, requiring manual intervention to restore normal operations.

Affected product and versions

Product
WSO2 WSO2 Universal Gateway, WSO2 Traffic Manager, WSO2 API Control Plane
Affected versions
4.5.0, 4.6.0, 4.7.0, 3.2.0, 3.2.1, 4.0.0, 4.1.0, 4.2.0, 4.3.0, 4.4.0, >= 4.5.0 < 4.5.0.55, >= 4.6.0 < 4.6.0.19, >= 4.0.0 < 4.0.0.390, >= 4.1.0 < 4.1.0.254, >= 4.2.0 < 4.2.0.194, >= 4.3.0 < 4.3.0.105, >= 4.4.0 < 4.4.0.69, >= 4.5.0 < 4.5.0.54, >= 4.6.0 < 4.6.0.18, >= 4.5.0 < 4.5.0.53
Fixed versions
4.5.0.55, 4.6.0.19, 4.0.0.390, 4.1.0.254, 4.2.0.194, 4.3.0.105, 4.4.0.69, 4.5.0.54, 4.6.0.18, 4.5.0.53

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that WSO2 WSO2 Universal Gateway, WSO2 Traffic Manager, WSO2 API Control Plane and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CWE
CWE-707
CVE-2026-4249 — WSO2 WSO2 Universal Gateway, WSO2 Traffic Manager, WSO2 API Control Plane | SECUFOCUS NOW