CVE-2026-108163
EUVD-2026-9631810.10.2026, 14:16
Pingvin Share X before 1.22.0 contains an ineffective rate limiting vulnerability because throttler TTL values specified in seconds are interpreted as milliseconds. Unauthenticated attackers can send effectively unthrottled requests to /api/auth/signIn, /api/auth/signIn/totp and /api/auth/resetPassword to brute-force passwords and TOTP codes.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
References