Description
RansomLook contains multiple weaknesses in its authentication endpoint that allow an unauthenticated remote attacker to enumerate valid usernames, perform unrestricted password-guessing attacks, and potentially exhaust application worker resources.

For local authentication, the login implementation previously checked whether a submitted username existed before invoking the password hash verification function. Requests containing a nonexistent username therefore returned significantly faster than requests for valid accounts, for which the computationally expensive password verification routine was executed. A remote attacker could measure these response-time differences to determine which usernames correspond to valid RansomLook accounts.

In addition, the /login endpoint did not restrict the number or frequency of failed authentication attempts. An attacker could consequently perform password brute-force, dictionary, password-spraying, or credential-stuffing attacks against known accounts without server-side throttling. For valid usernames, each authentication attempt also invokes the password key-derivation function, which consumes a significant amount of CPU time. A sufficiently high rate of login attempts could therefore occupy the application's synchronous Gunicorn workers and cause a denial of service affecting the entire application.

The issue has been addressed by always performing password verification using a randomly generated dummy password hash when the supplied username does not exist, eliminating the username-dependent timing discrepancy. Failed authentication attempts are additionally rate-limited per client IP address using Valkey/Redis, with five failed attempts within five minutes resulting in a one-hour block. The reverse-proxy configuration was also updated so that the application derives the client address from a trusted X-Forwarded-For value that cannot be overridden by a client-supplied header.
Published: 2026-08-24
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Account compromise and denial of service
Action: Immediate Patch
AI Analysis

Impact

CWE-307: The login endpoint in the RansomLook application has a flaw that allows an attacker to discover existing usernames by measuring response times. The system performs password verification only after confirming that a username exists, so requests for unknown usernames return quickly, while valid usernames trigger a computationally expensive password hash check. By comparing the timings, an attacker can enumerate accounts. In addition, there is no throttling on failed login attempts, so an attacker can execute brute-force, dictionary, or credential-stuffing attacks against known usernames, consuming CPU resources through repeated hashing. If performed at a high rate, this can exhaust Gunicorn workers and cause a denial of service for legitimate traffic.

Affected Systems

The vulnerability affects the RansomLook web application developed by ransomlook. No specific version numbers are listed in the advisory, so any deployment running the affected application may be at risk.

Risk and Exploitability

The CVSS base score of 8.8 classifies this as high severity, reflecting the ability for an unauthenticated attacker to enumerate accounts and carry out unrestricted brute-force attempts. The lack of an EPSS score means we currently have no estimate of exploit probability, but the vulnerability is publicly documented and not listed in the CISA KEV. Attackers can exploit it remotely over HTTP or HTTPS by sending crafted login requests, measuring timing differences, and performing rapid authentication attempts without encountering server-side throttling. If exploited, the attacker could compromise user credentials and disrupt service availability.

Generated by OpenCVE AI on August 24, 2026 at 21:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the patched RansomLook release that includes the authentication fixes and dummy hash verification.
  • Configure the application to enforce client‑IP based authentication attempt throttling; for example, five failures in five minutes should trigger a one‑hour block using Valkey/Redis or a similar in‑memory store.
  • Configure the reverse‑proxy to forward a trusted X‑Forwarded‑For header and ensure the application only accepts that header from the trusted reverse‑proxy, ignoring any client‑supplied X‑Forwarded‑For header.

Generated by OpenCVE AI on August 24, 2026 at 21:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Ransomlook
Ransomlook ransomlook
Vendors & Products Ransomlook
Ransomlook ransomlook

Mon, 24 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description RansomLook contains multiple weaknesses in its authentication endpoint that allow an unauthenticated remote attacker to enumerate valid usernames, perform unrestricted password-guessing attacks, and potentially exhaust application worker resources. For local authentication, the login implementation previously checked whether a submitted username existed before invoking the password hash verification function. Requests containing a nonexistent username therefore returned significantly faster than requests for valid accounts, for which the computationally expensive password verification routine was executed. A remote attacker could measure these response-time differences to determine which usernames correspond to valid RansomLook accounts. In addition, the /login endpoint did not restrict the number or frequency of failed authentication attempts. An attacker could consequently perform password brute-force, dictionary, password-spraying, or credential-stuffing attacks against known accounts without server-side throttling. For valid usernames, each authentication attempt also invokes the password key-derivation function, which consumes a significant amount of CPU time. A sufficiently high rate of login attempts could therefore occupy the application's synchronous Gunicorn workers and cause a denial of service affecting the entire application. The issue has been addressed by always performing password verification using a randomly generated dummy password hash when the supplied username does not exist, eliminating the username-dependent timing discrepancy. Failed authentication attempts are additionally rate-limited per client IP address using Valkey/Redis, with five failed attempts within five minutes resulting in a one-hour block. The reverse-proxy configuration was also updated so that the application derives the client address from a trusted X-Forwarded-For value that cannot be overridden by a client-supplied header.
Title RansomLook Login Endpoint Allows Timing-Based Username Enumeration and Unthrottled Authentication Attempts
Weaknesses CWE-307
CWE-400
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Ransomlook Ransomlook
cve-icon MITRE

Status: PUBLISHED

Assigner: CIRCL

Published:

Updated: 2026-08-24T20:07:41.242Z

Reserved: 2026-08-24T19:19:59.060Z

Link: CVE-2026-78551

cve-icon Vulnrichment

Updated: 2026-08-24T20:07:38.280Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T20:17:23.927

Modified: 2026-08-26T16:49:18.760

Link: CVE-2026-78551

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:15:07Z

Weaknesses
  • CWE-307

    Improper Restriction of Excessive Authentication Attempts

  • CWE-400

    Uncontrolled Resource Consumption