CVE-2026-84856 Overview
CVE-2026-84856 is a denial of service vulnerability in rowboatlabs/rowboat versions up to 0.9.1. The flaw resides in the request.text and req.json handling within apps/rowboat/app/api/composio/webhook/route.ts, part of the Composio Webhook Endpoint component. Remote attackers can trigger the condition without authentication by sending crafted request bodies to the webhook route. The exploit is publicly available, increasing the likelihood of opportunistic abuse against exposed instances. The maintainers addressed the issue in version 0.9.2 by deleting the legacy Next.js application entirely rather than patching it, meaning no residual security control remains in the removed code path.
Critical Impact
Unauthenticated remote attackers can exhaust server resources through the Composio webhook endpoint, disrupting availability of Rowboat deployments.
Affected Products
- rowboatlabs rowboat versions up to and including 0.9.1
- Component: Composio Webhook Endpoint (apps/rowboat/app/api/composio/webhook/route.ts)
- Legacy Next.js application within the Rowboat repository
Discovery Timeline
- 2026-09-02 - CVE-2026-84856 published to NVD
- 2026-09-02 - Last updated in NVD database
Technical Details for CVE-2026-84856
Vulnerability Analysis
The vulnerability is classified under CWE-404: Improper Resource Shutdown or Release. The Composio Webhook route in Rowboat parses incoming HTTP request bodies using request.text() and req.json() without enforcing size limits or resource ceilings. When invoked, these methods buffer the full request body into memory before validation or authentication takes place. An attacker can submit large or malformed payloads that force the Node.js runtime to allocate excessive memory, degrading responsiveness or crashing the process.
Because the endpoint is reachable over the network and requires no authentication, exploitation is trivial. Repeated requests amplify the impact, producing sustained denial of service against the hosting infrastructure.
Root Cause
The route handler consumes the entire request body prior to any authentication, authorization, or content-length validation. Node.js buffers the payload in memory, and no upstream middleware bounds the input size. This missing resource governance is the direct cause of the denial of service condition.
Attack Vector
An unauthenticated remote attacker sends HTTP POST requests to the Composio webhook route with oversized or repeatedly issued bodies. The server allocates memory to buffer each payload through request.text() or req.json(). Sustained requests exhaust available memory or CPU, causing degradation or termination of the Rowboat service. Public proof-of-concept material is referenced in the GitHub CVE Report.
No verified exploitation code is provided here. Refer to the linked advisory for technical reproduction details.
Detection Methods for CVE-2026-84856
Indicators of Compromise
- Unusually large HTTP POST bodies targeting the /api/composio/webhook route path
- Sustained bursts of unauthenticated requests from a small set of source addresses toward the Composio webhook endpoint
- Rowboat Node.js process memory or CPU consumption climbing rapidly with corresponding request spikes
Detection Strategies
- Inspect reverse proxy or web application firewall logs for oversized Content-Length values on requests to /api/composio/webhook
- Correlate application error logs showing out-of-memory conditions, event loop stalls, or process restarts with inbound webhook traffic
- Baseline normal Composio webhook request rates and payload sizes to identify anomalous surges
Monitoring Recommendations
- Enable request-rate and body-size telemetry on the ingress layer fronting Rowboat deployments
- Alert on repeated 5xx responses or health-check failures originating from the Rowboat service
- Track container or host memory saturation metrics for hosts running the affected Next.js application
How to Mitigate CVE-2026-84856
Immediate Actions Required
- Upgrade Rowboat to version 0.9.2 or later, which removes the vulnerable legacy Next.js application
- Restrict network exposure of the Composio webhook endpoint to trusted sources using firewall or reverse proxy rules
- Enforce request body size limits at the ingress or reverse proxy layer while planning the upgrade
Patch Information
The fix is delivered in Rowboat Release v0.9.2. According to the advisory, the legacy Next.js application containing apps/rowboat/app/api/composio/webhook/route.ts was deleted rather than patched in place. Upgrading the affected component is the recommended remediation path. Additional context is available at VulDB CVE-2026-84856.
Workarounds
- Place a reverse proxy such as NGINX or a WAF in front of Rowboat and cap client_max_body_size to a small value appropriate for legitimate Composio webhook payloads
- Apply rate limiting on the /api/composio/webhook path to blunt volumetric abuse
- Disable or block the Composio webhook route at the network edge if the integration is unused
# Configuration example: NGINX body-size and rate limiting for the Composio webhook route
http {
limit_req_zone $binary_remote_addr zone=composio_wh:10m rate=5r/s;
server {
location /api/composio/webhook {
client_max_body_size 32k;
limit_req zone=composio_wh burst=10 nodelay;
proxy_pass http://rowboat_upstream;
}
}
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
