Impact
A concurrency flaw in the doUpdateLicenseKey function of vvbbnn00 WARP‑Clash‑API lets multiple simultaneous update requests interfere with one another, creating a race condition. The flaw can cause an invalid or expired license key to be accepted or a legitimate one to be invalidated, allowing an attacker to use the API without proper authorization or deny service to legitimate users. The bug is triggered by concurrent traffic to the same endpoint and does not require initial authentication or privileged access, although its exploitation is reported as difficult and of high complexity.
Affected Systems
The vulnerability affects all releases of WARP‑Clash‑API issued by vvbbnn00 up to the commit hash c7bf2360073959861219b422e51ae86411051b46. The product does not implement versioning, so all prior builds are considered vulnerable. The maintainer has ceased support, and no official patch has been released.
Risk and Exploitability
The CVSS score of 2.3 denotes low severity, and the EPSS score is in the < 1% range. The flaw is not listed in CISA’s KEV catalog. While the attack can be launched remotely, its exploitation requires high complexity and is reported as difficult, implying that successful automated attacks are unlikely without further skill or privileged access. Consequently, the overall risk is moderate, but the probability of exploitation remains low.
OpenCVE Enrichment