Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-11922

Опубликовано: 24 июл. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass rate-limiting on the POST /api/v1/login and self password-change endpoints by rotating the X-Forwarded-For header. The rate limiter keys requests by request.client.host, which is derived from the X-Forwarded-For header when Uvicorn is launched with --proxy-headers --forwarded-allow-ips *. This configuration allows clients to control the value of request.client.host, effectively bypassing rate-limiting protections. This vulnerability leaves the affected endpoints open to unthrottled credential guessing attacks.

EPSS

Процентиль: 8%
0.00179
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 6.5
github
2 месяца назад

A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass rate-limiting on the `POST /api/v1/login` and self password-change endpoints by rotating the `X-Forwarded-For` header. The rate limiter keys requests by `request.client.host`, which is derived from the `X-Forwarded-For` header when Uvicorn is launched with `--proxy-headers --forwarded-allow-ips *`. This configuration allows clients to control the value of `request.client.host`, effectively bypassing rate-limiting protections. This vulnerability leaves the affected endpoints open to unthrottled credential guessing attacks.

EPSS

Процентиль: 8%
0.00179
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-290