๐Ÿ” CVE Alert

CVE-2026-77357

UNKNOWN 0.0

Mesop: DoS in /hot-reload endpoint allows unauthenticated attacker to exhaust worker threads and crash the server

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.3, applications running in debug mode expose a GET /hot-reload endpoint whose unbounded loop depends on the user-supplied counter parameter, allowing an unauthenticated attacker to hold worker threads with high counter values until the worker pool is exhausted and the server becomes unavailable. A single unauthenticated attacker can crash the Mesop server with minimal effort. Because the attack leverages worker exhaustion, the server remains unresponsive until it is manually restarted. This issue is fixed in version 1.3.3.

CWE CWE-400 CWE-834
Vendor mesop-dev
Product mesop
Published Aug 25, 2026
Stay Ahead of the Next One

Get instant alerts for mesop-dev mesop

Be the first to know when new unknown vulnerabilities affecting mesop-dev mesop are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

mesop-dev / mesop
< 1.3.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/mesop-dev/mesop/security/advisories/GHSA-8p72-497j-83mx github.com: https://github.com/mesop-dev/mesop/commit/2b8e7f2c349c9e2eec202f46b07bada83061ce2d github.com: https://github.com/mesop-dev/mesop/releases/tag/v1.3.3