Количество 2
Количество 2
CVE-2026-56272
Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instead of the OWASP-recommended minimum of 10 rounds. Attackers can crack password hashes approximately 30 times faster with modern GPU hardware, potentially compromising all user accounts in a database breach scenario.
GHSA-x2g5-fvc2-gqvp
Flowise has Insufficient Password Salt Rounds
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-56272 Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instead of the OWASP-recommended minimum of 10 rounds. Attackers can crack password hashes approximately 30 times faster with modern GPU hardware, potentially compromising all user accounts in a database breach scenario. | CVSS3: 4.1 | 0% Низкий | 3 месяца назад | |
GHSA-x2g5-fvc2-gqvp Flowise has Insufficient Password Salt Rounds | CVSS3: 4.1 | 0% Низкий | 6 месяцев назад |
Уязвимостей на страницу