Description
Pingvin Share X before 1.22.0 contains an ineffective rate limiting vulnerability because throttler TTL values specified in seconds are interpreted as milliseconds. Unauthenticated attackers can send effectively unthrottled requests to /api/auth/signIn, /api/auth/signIn/totp and /api/auth/resetPassword to brute-force passwords and TOTP codes.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Sat, 10 Oct 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pingvin Share X before 1.22.0 contains an ineffective rate limiting vulnerability because throttler TTL values specified in seconds are interpreted as milliseconds. Unauthenticated attackers can send effectively unthrottled requests to /api/auth/signIn, /api/auth/signIn/totp and /api/auth/resetPassword to brute-force passwords and TOTP codes. | |
| Title | Pingvin Share X before 1.22.0 Ineffective Authentication Rate Limiting via Throttler TTL | |
| Weaknesses | CWE-307 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-10T13:55:14.177Z
Reserved: 2026-10-09T15:41:44.133Z
Link: CVE-2026-108163
No data.
Status : Received
Published: 2026-10-10T14:16:37.530
Modified: 2026-10-10T14:16:37.530
Link: CVE-2026-108163
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-307
Improper Restriction of Excessive Authentication Attempts