CVE-2026-108162
EUVD-2026-9631710.10.2026, 14:16
Pingvin Share X before 1.22.0 contains a rate limit bypass vulnerability that allows unauthenticated remote attackers to evade per-IP throttling because backend/src/main.ts unconditionally trusts proxy headers. Attackers can rotate spoofed X-Forwarded-For values against /api/auth/signIn, /api/auth/signIn/totp, and /api/auth/resetPassword to brute-force passwords and TOTP codes and forge logged client IP addresses.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Common Weakness Enumeration
References