Description
A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This affects the function doUpdateLicenseKey. The manipulation results in race condition. The attack can be launched remotely. The attack requires a high level of complexity. The exploitability is reported as difficult. The exploit has been made public and could be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-09-13
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Race condition in license key update enables unauthorized license use
Action: Assess Impact
AI Analysis

Impact

A concurrency flaw in the doUpdateLicenseKey function of vvbbnn00 WARP‑Clash‑API lets multiple simultaneous update requests interfere with one another, creating a race condition. The flaw can cause an invalid or expired license key to be accepted or a legitimate one to be invalidated, allowing an attacker to use the API without proper authorization or deny service to legitimate users. The bug is triggered by concurrent traffic to the same endpoint and does not require initial authentication or privileged access, although its exploitation is reported as difficult and of high complexity.

Affected Systems

The vulnerability affects all releases of WARP‑Clash‑API issued by vvbbnn00 up to the commit hash c7bf2360073959861219b422e51ae86411051b46. The product does not implement versioning, so all prior builds are considered vulnerable. The maintainer has ceased support, and no official patch has been released.

Risk and Exploitability

The CVSS score of 2.3 denotes low severity, and the EPSS score is in the < 1% range. The flaw is not listed in CISA’s KEV catalog. While the attack can be launched remotely, its exploitation requires high complexity and is reported as difficult, implying that successful automated attacks are unlikely without further skill or privileged access. Consequently, the overall risk is moderate, but the probability of exploitation remains low.

Generated by OpenCVE AI on September 15, 2026 at 17:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Restrict network access to the WARP‑Clash‑API so that only trusted hosts or internal networks can invoke the doUpdateLicenseKey endpoint
  • Implement application‑level serialization or locking around license key update requests to eliminate the race condition
  • Engage with the maintainers to request a patch or plan migration to an actively supported alternative product

Generated by OpenCVE AI on September 15, 2026 at 17:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This affects the function doUpdateLicenseKey. The manipulation results in race condition. The attack can be launched remotely. The attack requires a high level of complexity. The exploitability is reported as difficult. The exploit has been made public and could be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.
Title vvbbnn00 WARP-Clash-API doUpdateLicenseKey race condition
First Time appeared Vvbbnn00
Vvbbnn00 warp-clash-api
Weaknesses CWE-362
CPEs cpe:2.3:a:vvbbnn00:warp-clash-api:*:*:*:*:*:*:*:*
Vendors & Products Vvbbnn00
Vvbbnn00 warp-clash-api
References
Metrics cvssV2_0

{'score': 4.6, 'vector': 'AV:N/AC:H/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Vvbbnn00 Warp-clash-api
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T18:04:04.916Z

Reserved: 2026-09-12T08:46:48.440Z

Link: CVE-2026-90505

cve-icon Vulnrichment

Updated: 2026-09-14T18:03:57.081Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T10:16:55.357

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90505

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:30:10Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')