CVE-2026-27460: medium-severity vulnerability in TandoorRecipes recipes
Tandoor Recipes Affected by Denial of Service via Recipe Import
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
Tandoor Recipes versions before 2.6.5 can crash or slow down significantly when an authenticated user uploads a specially crafted large ZIP file during recipe import. This allows someone with login access to disrupt the service for other users.
CWE-409 (Improper Restriction of Rendered UI Layers or Frames) manifests as a DoS vulnerability in the recipe import endpoint. An authenticated attacker can upload a ZIP bomb to exhaust server resources (CPU, memory, or disk I/O), causing denial of service. The vulnerability requires prior authentication and is mitigated in version 2.6.5 through improved input validation and resource limits.
In the same product, most dangerous first.