Medium severity6.5NVD Advisory· Published Apr 10, 2026· Updated Apr 14, 2026
CVE-2026-27460
CVE-2026-27460
Description
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. Prior to 2.6.5, a critical Denial of Service (DoS) vulnerability was in the recipe import functionality. This vulnerability allows an authenticated user to crash the server or make a significantly degrade its performance by uploading a large size ZIP file (ZIP Bomb). This vulnerability is fixed in 2.6.5.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/TandoorRecipes/recipes/security/advisories/GHSA-w8pq-4pwf-r2m8nvdExploitVendor Advisory
News mentions
1- The hidden smart fridge risks that emerge years after purchaseHelp Net Security · May 12, 2026