Versions of Wavelog 2.1.1 and earlier contain a DOS (Denial-of-Service) attack vector. It is recommended that users upgrade to Wavelog 2.1.2 or later as soon as possible, using publicly available instances of these older versions.
The test results for the proof-of-concept (POC) showed that it was possible to trigger the vulnerability as long as access to the target webpage could be achieved. For the 2C 4G server, a single attack on the host could cause the server to crash. For the 20C server, a single attack on the host could render the webpage unusable.
I have agreed with the Wavelog team to publicly disclose details about this vulnerability two weeks after the release of the new version (one week after the initial release).