CVE-2026-86075High· 7.5▾ Twilightn8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the OAuth Dynamic Client Registration endpoint bounded redirect_uris but accepted arbitrarily large client_name and grant_types values. An unauthenticated re…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
0.3% → 0.3%
7.5 → 8.7
8.7 → 7.5
7.5 → 8.7
8.7 → 7.5
7.5 → 8.7
8.7 → 7.5
7.5 → 8.7
8.7 → 7.5
7.5 → 8.7
8.7 → 7.5
7.5 → 8.7
8.7 → 7.5
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the OAuth Dynamic Client Registration endpoint bounded redirect_uris but accepted arbitrarily large client_name and grant_types values. An unauthenticated remote caller could repeatedly persist oversized values in oauth_clients and exhaust database storage. The affected validation is in packages/cli/src/modules/oauth-server/oauth-server.service.ts, including MAX_CLIENT_NAME_LENGTH and MAX_GRANT_TYPES. This issue is fixed in versions 2.37.7 and 2.38.2.
n8n < 2.37.7n8n >= 2.38.0, < 2.38.2Upgrade past the affected range:
n8n 2.38.2Affected packages:
n8n >= 2.38.0, < 2.38.2n8n < 2.37.7Patched in:
n8n 2.38.2n8n 2.37.7Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-86083High· 8.8n8n is an open source workflow automation platform
CVE-2026-86084Medium· 5.5n8n is an open source workflow automation platform
CVE-2026-86085Medium· 4.9n8n is an open source workflow automation platform
CVE-2026-86994Medium· 4.3n8n is an open source workflow automation platform
CVE-2026-86076High· 8.8n8n is an open source workflow automation platform
CVE-2026-86077Medium· 6.5n8n is an open source workflow automation platform