CVE-2022-21689
HIGHOnionShare < 2.5 - Denial of Service via Concurrent Upload Limit Exhaustion
Title source: llmDescription
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions the receive mode limits concurrent uploads to 100 per second and blocks other uploads in the same second, which can be triggered by a simple script. An adversary with access to the receive mode can block file upload for others. There is no way to block this attack in public mode due to the anonymity properties of the tor network.
References (2)
Core 2
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/onionshare/onionshare/releases/tag/v2.5
Third Party Advisory x_refsource_confirm
https://github.com/onionshare/onionshare/security/advisories/GHSA-jh82-c5jw-pxpc
Scores
CVSS v3
7.5
EPSS
0.0137
EPSS Percentile
68.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-400
Status
published
Products (2)
onionshare/onionshare
< 2.5
pypi/onionshare-cli
0 - 2.5PyPI
Published
Jan 18, 2022
Tracked Since
Feb 18, 2026