Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 10 Oct 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Smp46
Smp46 pingvin-share-x |
|
| Vendors & Products |
Smp46
Smp46 pingvin-share-x |
Sat, 10 Oct 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pingvin Share X before 1.22.0 contains an ineffective rate limiting vulnerability because throttler TTL values specified in seconds are interpreted as milliseconds. Unauthenticated attackers can send effectively unthrottled requests to /api/auth/signIn, /api/auth/signIn/totp and /api/auth/resetPassword to brute-force passwords and TOTP codes. | |
| Title | Pingvin Share X before 1.22.0 Ineffective Authentication Rate Limiting via Throttler TTL | |
| Weaknesses | CWE-307 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-10T13:55:14.177Z
Reserved: 2026-10-09T15:41:44.133Z
Link: CVE-2026-108163
No data.
Status : Received
Published: 2026-10-10T14:16:37.530
Modified: 2026-10-10T14:16:37.530
Link: CVE-2026-108163
No data.
OpenCVE Enrichment
Updated: 2026-10-10T15:30:17Z
