Pingvin Share X before 1.22.0 contains an ineffective rate limiting vulnerability because throttler TTL values specified in seconds are interpreted as milliseconds. Unauthenticated attackers can send effectively unthrottled requests to /api/auth/signIn, /api/auth/signIn/totp and /api/auth/resetPassword to brute-force passwords and TOTP codes.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 10 Oct 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Smp46
Smp46 pingvin-share-x |
|
| Vendors & Products |
Smp46
Smp46 pingvin-share-x |
Sat, 10 Oct 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Pingvin Share X before 1.22.0 contains an ineffective rate limiting vulnerability because throttler TTL values specified in seconds are interpreted as milliseconds. Unauthenticated attackers can send effectively unthrottled requests to /api/auth/signIn, /api/auth/signIn/totp and /api/auth/resetPassword to brute-force passwords and TOTP codes. | |
| Title | Pingvin Share X before 1.22.0 Ineffective Authentication Rate Limiting via Throttler TTL | |
| Weaknesses | CWE-307 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-10T13:55:14.177Z
Reserved: 2026-10-09T15:41:44.133Z
Link: CVE-2026-108163
No data.
Status : Received
Published: 2026-10-10T14:16:37.530
Modified: 2026-10-10T14:16:37.530
Link: CVE-2026-108163
No data.
OpenCVE Enrichment
Updated: 2026-10-10T15:30:17Z
Weaknesses