Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-108162

MEDIUM NVD
CVSS Score 6.5
Severity MEDIUM
Published Oct 10, 2026
Vendor unknown

Description

Pingvin Share X before 1.22.0 contains a rate limit bypass vulnerability that allows unauthenticated remote attackers to evade per-IP throttling because backend/src/main.ts unconditionally trusts proxy headers. Attackers can rotate spoofed X-Forwarded-For values against /api/auth/signIn, /api/auth/signIn/totp, and /api/auth/resetPassword to brute-force passwords and TOTP codes and forge logged client IP addresses.

References