CVE-2024-47212: Snowplow Iglu Server
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
An issue was discovered in Iglu Server 0.13.0 and below. It involves sending very large payloads to a particular API endpoint of Iglu Server and can render it completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would eventually halt.
Affected products
- Snowplow Iglu Server: before 0.13.1 (fixed in 0.13.1)
Published 2025-04-03. Last modified 2026-06-17.