{"id":"CVE-2026-66761","title":"SAP Approuter does not enforce sufficient flow control in certain functionality","summary":"SAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could send high volumes of data without consuming responses, causing unbounded memory growth. This results in a low impact o…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-770"],"vendor":"sap","product":"approuter","affected":["approuter < 23.0.0"],"patched":["approuter 23.0.0"],"published":"2026-08-11","updated":"2026-09-08","sourceUpdated":"2026-09-08T20:20:15.443","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-66761","references":[{"url":"https://me.sap.com/notes/3786038","label":"cna@sap.com"},{"url":"https://url.sap/sapsecuritypatchday","label":"cna@sap.com"}],"tags":["nvd"],"epss":0.00382,"epssPercentile":0.29332,"ingestedAt":"2026-09-08T21:11:12.274Z","slug":"CVE-2026-66761","body":"## Overview\n\nSAP Approuter does not enforce sufficient flow control in certain functionality. An attacker with low privileges could send high volumes of data without consuming responses, causing unbounded memory growth. This results in a low impact on availability. There is no impact on confidentiality and integrity.\n\n## Affected\n\n- `approuter < 23.0.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `approuter 23.0.0`","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}