n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the MCP OAuth client registration endpoint accepted unauthenticated requests and stored client data without adequate resource controls. An unauthenticated remote attacker could exhaust server memory resources by sending large registration payloads, rendering the n8n instance unavailable. The MCP enable/disable toggle gates MCP access but did not restrict client registrations, meaning the endpoint is reachable regardless of whether MCP access is enabled on the instance. This issue has been patched in versions 1.123.32, 2.17.4, and 2.18.1.
References
| Link | Resource |
|---|---|
| https://github.com/n8n-io/n8n/security/advisories/GHSA-49m9-pgww-9vq6 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
06 May 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
N8n n8n
N8n |
|
| CPE | cpe:2.3:a:n8n:n8n:2.18.0:*:*:*:enterprise:node.js:*:* cpe:2.3:a:n8n:n8n:*:*:*:*:enterprise:node.js:*:* |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| References | () https://github.com/n8n-io/n8n/security/advisories/GHSA-49m9-pgww-9vq6 - Vendor Advisory |
04 May 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-04 19:16
Updated : 2026-05-06 17:16
NVD link : CVE-2026-42236
Mitre link : CVE-2026-42236
CVE.ORG link : CVE-2026-42236
JSON object : View
Products Affected
n8n
- n8n
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
