LOWVulnerability

CVE-2026-77357

Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.3, applications running in debug mode expose a GET /hot-reload endpoint whose unbounded loop depends on the user-supplied counter parameter, allowing an unauthenticated attacker to hold worker threads with high counter values until the worker pool is exhausted and the server becomes unavailable. A single unauthenticated attacker can crash the Mesop server with minimal effort. Because the attack leverages worker exhaustion, the server remains unresponsive until it is manually restarted. This issue is fixed in version 1.3.3.

Properties

epss_score
0.00304
cve_id
CVE-2026-77357
signal_observed_at
2026-09-15T21:12:47+00:00
published_at
2026-08-25T21:17:46.090
last_modified
2026-09-09T21:09:13.080
epss_percentile
0.23085

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (2)

[Weakness]Uncontrolled Resource Consumption
[Weakness]Excessive Iteration

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-77357 — Ninja Signal Threat Intelligence | Ninja Signal