Common Weakness Enumeration

CWE-307

Allowed

Improper Restriction of Excessive Authentication Attempts

Abstraction: Base · Status: Draft

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

1032 vulnerabilities reference this CWE, most recent first.

GHSA-G45J-9379-J77G

Vulnerability from github – Published: 2026-06-01 06:30 – Updated: 2026-06-01 06:30
VLAI
Details

A vulnerability was detected in unitedbyai droidclaw up to 0.5.3. The affected element is an unknown function of the file server/src/routes/pairing.ts of the component claim Endpoint. The manipulation results in improper restriction of excessive authentication attempts. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-10216"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-307"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-06-01T04:16:20Z",
    "severity": "LOW"
  },
  "details": "A vulnerability was detected in unitedbyai droidclaw up to 0.5.3. The affected element is an unknown function of the file server/src/routes/pairing.ts of the component claim Endpoint. The manipulation results in improper restriction of excessive authentication attempts. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.",
  "id": "GHSA-g45j-9379-j77g",
  "modified": "2026-06-01T06:30:25Z",
  "published": "2026-06-01T06:30:25Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-10216"
    },
    {
      "type": "WEB",
      "url": "https://github.com/unitedbyai/droidclaw/issues/14"
    },
    {
      "type": "WEB",
      "url": "https://gist.github.com/YLChen-007/2639ccaefd55ef4309953b76bc4c737e/raw"
    },
    {
      "type": "WEB",
      "url": "https://github.com/unitedbyai/droidclaw"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/cve/CVE-2026-10216"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/submit/821936"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/vuln/367495"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/vuln/367495/cti"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ]
}

GHSA-G66J-37WX-VRJ5

Vulnerability from github – Published: 2026-03-17 18:30 – Updated: 2026-03-17 18:30
VLAI
Details

JetKVM before 0.5.4 does not rate limit login requests, enabling brute-force attempts to guess credentials.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-32295"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-307"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-03-17T18:16:16Z",
    "severity": "CRITICAL"
  },
  "details": "JetKVM before 0.5.4 does not rate limit login requests, enabling brute-force attempts to guess credentials.",
  "id": "GHSA-g66j-37wx-vrj5",
  "modified": "2026-03-17T18:30:33Z",
  "published": "2026-03-17T18:30:33Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32295"
    },
    {
      "type": "WEB",
      "url": "https://eclypsium.com/blog/kvm-devices-the-keys-to-your-kingdom-are-hanging-on-the-network"
    },
    {
      "type": "WEB",
      "url": "https://github.com/jetkvm/kvm/releases/tag/release%2F0.5.4"
    },
    {
      "type": "WEB",
      "url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-26-076-01.json"
    },
    {
      "type": "WEB",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32295"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ]
}

GHSA-G6Q4-W3J3-JFC4

Vulnerability from github – Published: 2024-09-05 15:33 – Updated: 2024-09-06 21:57
VLAI
Summary
Windmill HTTP Request users.rs excessive authentication in github.com/windmill-labs/windmill
Details

A vulnerability was found in Windmill 1.380.0. It has been classified as problematic. Affected is an unknown function of the file backend/windmill-api/src/users.rs of the component HTTP Request Handler. The manipulation leads to improper restriction of excessive authentication attempts. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. Upgrading to version 1.390.1 is able to address this issue. The patch is identified as acfe7786152f036f2476f93ab5536571514fa9e3. It is recommended to upgrade the affected component.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "Go",
        "name": "github.com/windmill-labs/windmill"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "last_affected": "1.61.1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2024-8462"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-307"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2024-09-06T21:57:28Z",
    "nvd_published_at": "2024-09-05T13:15:12Z",
    "severity": "MODERATE"
  },
  "details": "A vulnerability was found in Windmill 1.380.0. It has been classified as problematic. Affected is an unknown function of the file backend/windmill-api/src/users.rs of the component HTTP Request Handler. The manipulation leads to improper restriction of excessive authentication attempts. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. Upgrading to version 1.390.1 is able to address this issue. The patch is identified as acfe7786152f036f2476f93ab5536571514fa9e3. It is recommended to upgrade the affected component.",
  "id": "GHSA-g6q4-w3j3-jfc4",
  "modified": "2024-09-06T21:57:28Z",
  "published": "2024-09-05T15:33:35Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8462"
    },
    {
      "type": "WEB",
      "url": "https://github.com/windmill-labs/windmill/commit/acfe7786152f036f2476f93ab5536571514fa9e3"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/windmill-labs/windmill"
    },
    {
      "type": "WEB",
      "url": "https://github.com/windmill-labs/windmill/releases/tag/v1.390.1"
    },
    {
      "type": "WEB",
      "url": "https://pkg.go.dev/vuln/GO-2024-3118"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/?ctiid.276630"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/?id.276630"
    },
    {
      "type": "WEB",
      "url": "https://vuldb.com/?submit.401826"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ],
  "summary": "Windmill HTTP Request users.rs excessive authentication in github.com/windmill-labs/windmill"
}

GHSA-G6WR-5R3P-F3V9

Vulnerability from github – Published: 2022-04-30 18:17 – Updated: 2024-02-09 03:32
VLAI
Details

Beck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when bad passwords are entered, which makes it easier for remote attackers to conduct brute force password guessing attacks.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2001-1339"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-307"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2001-05-24T04:00:00Z",
    "severity": "HIGH"
  },
  "details": "Beck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when bad passwords are entered, which makes it easier for remote attackers to conduct brute force password guessing attacks.",
  "id": "GHSA-g6wr-5r3p-f3v9",
  "modified": "2024-02-09T03:32:51Z",
  "published": "2022-04-30T18:17:49Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2001-1339"
    },
    {
      "type": "WEB",
      "url": "http://cert.uni-stuttgart.de/archive/bugtraq/2001/06/msg00010.html"
    },
    {
      "type": "WEB",
      "url": "http://www.iss.net/security_center/static/6605.php"
    },
    {
      "type": "WEB",
      "url": "http://www.kb.cert.org/vuls/id/198979"
    },
    {
      "type": "WEB",
      "url": "http://www.securityfocus.com/archive/1/186418"
    },
    {
      "type": "WEB",
      "url": "http://www.securityfocus.com/bid/2771"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-G6XM-F9XP-QQ35

Vulnerability from github – Published: 2026-09-30 23:26 – Updated: 2026-09-30 23:26
VLAI
Summary
Russh: Configured server auth-attempt cap is not enforced in the USERAUTH_REQUEST runtime path
Details

Details

Affected versions and vulnerable location

  • Confirmed present on default branch main at HEAD 0089c89c94753bebbec12b956c07a1cd38740379.
  • Crate version at HEAD: 0.62.4.
  • Vulnerable locations on current default branch:
  • russh/src/server/mod.rs:91 (pub max_auth_attempts: usize)
  • russh/src/server/mod.rs:121 (default max_auth_attempts: 10)
  • russh/src/server/encrypted.rs:89 (USERAUTH_REQUEST dispatch into auth handler path)
  • russh/src/server/encrypted.rs:98 (self.common.auth_attempts += 1)
  • russh/src/server/encrypted.rs:53 (only runtime read of auth_attempts, used for initial reject timing, not attempt limiting)
  • Default-branch history check did not show a newer merged commit adding enforcement against config.max_auth_attempts.

Reachability trace verified

  1. Entry point: exported server API server::run_stream in russh/src/server/mod.rs:1049.
  2. Session run loop in russh/src/server/session.rs processes incoming packets and calls reply(...) (server/session.rs:725).
  3. reply forwards encrypted packets to session.server_read_encrypted(...) (server/mod.rs:1221).
  4. server_read_encrypted routes USERAUTH_REQUEST to enc.server_read_auth_request(...) (server/encrypted.rs:89).
  5. On each request, self.common.auth_attempts += 1 executes (server/encrypted.rs:98).
  6. No comparison against self.common.config.max_auth_attempts is present in this runtime flow.

PoC

Reproduction steps and observed output

I did not run a full server process in this environment because Rust tooling is unavailable. I verified the issue from source and command output on the audited tree.

  1. Show where max_auth_attempts appears:
rtk rg -n "max_auth_attempts" .scratch/russh/russh/src/server/mod.rs .scratch/russh/russh/src/server/encrypted.rs .scratch/russh/russh/src/server/session.rs

Observed:

.scratch/russh/russh/src/server/mod.rs:91:    pub max_auth_attempts: usize,
.scratch/russh/russh/src/server/mod.rs:121:            max_auth_attempts: 10,
.scratch/russh/russh/src/server/mod.rs:148:            .field("max_auth_attempts", &self.max_auth_attempts)
  1. Show runtime auth-attempt handling:
rtk rg -n "auth_attempts == 0|auth_attempts \\+= 1" .scratch/russh/russh/src/server/encrypted.rs

Observed:

53:        let initial_none_rejection_wait_until = if self.common.auth_attempts == 0 {
98:                self.common.auth_attempts += 1;
  1. Show production entrypoint-to-auth path references:
rtk rg -n "pub async fn run_stream|match reply\\(|server_read_encrypted\\(|server_read_auth_request\\(" .scratch/russh/russh/src/server/mod.rs .scratch/russh/russh/src/server/session.rs .scratch/russh/russh/src/server/encrypted.rs

Observed:

.scratch/russh/russh/src/server/encrypted.rs:89:                enc.server_read_auth_request(
.scratch/russh/russh/src/server/session.rs:725:                            match reply(&mut self, &mut handler, &mut pkt).await {
.scratch/russh/russh/src/server/mod.rs:1049:pub async fn run_stream<H, R>(
.scratch/russh/russh/src/server/mod.rs:1221:    session.server_read_encrypted(handler, pkt).await
  1. Toolchain check:
cargo --version

Observed:

/bin/bash: line 1: cargo: command not found

Impact

Attacker model

  • Attacker: unauthenticated remote client with TCP reachability to a russh-backed SSH service.
  • Preconditions: deployer expects server::Config.max_auth_attempts to cap attempts.
  • Impact: repeated USERAUTH_REQUEST attempts continue for a single connection beyond configured limit, increasing online guessing opportunity and backend auth workload.

Suggested fix

Enforce max_auth_attempts in the USERAUTH_REQUEST branch before invoking auth-method handlers, and fail closed once threshold is reached.

Concrete patch direction in russh/src/server/encrypted.rs:

if self.common.config.max_auth_attempts > 0
    && self.common.auth_attempts >= self.common.config.max_auth_attempts
{
    self.common.disconnect(
        Disconnect::NoMoreAuthMethodsAvailable,
        "Too many authentication attempts",
        "",
    )?;
    return Ok(());
}

How it was found and a note on tooling

The researcher synthesized three lens outputs, then revalidated each claim against current main: source presence and commit history, advisory overlap checks in both GitHub advisories and OSV, entrypoint-to-sink reachability, attacker-model realism, and execution-claim integrity. The researcher used gh, git, rg, and direct source inspection under .scratch/russh. Because Rust tooling is unavailable in this worker, this report is intentionally marked source-only.

AI assistance was used while investigating this and while drafting this report. The finding was verified by reading the cited code at HEAD. The vulnerability was not executed it, and that limit is stated plainly above rather than left implied.

Credits: arpitjain099.

Show details on source website

{
  "affected": [
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 0.62.5"
      },
      "package": {
        "ecosystem": "crates.io",
        "name": "russh"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0.62.6"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-102825"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-307"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-30T23:26:17Z",
    "nvd_published_at": "2026-09-29T19:17:24Z",
    "severity": "LOW"
  },
  "details": "### Details\n\n#### Affected versions and vulnerable location\n\n- Confirmed present on default branch `main` at HEAD `0089c89c94753bebbec12b956c07a1cd38740379`.\n- Crate version at HEAD: `0.62.4`.\n- Vulnerable locations on current default branch:\n  - `russh/src/server/mod.rs:91` (`pub max_auth_attempts: usize`)\n  - `russh/src/server/mod.rs:121` (default `max_auth_attempts: 10`)\n  - `russh/src/server/encrypted.rs:89` (`USERAUTH_REQUEST` dispatch into auth handler path)\n  - `russh/src/server/encrypted.rs:98` (`self.common.auth_attempts += 1`)\n  - `russh/src/server/encrypted.rs:53` (only runtime read of `auth_attempts`, used for initial reject timing, not attempt limiting)\n- Default-branch history check did not show a newer merged commit adding enforcement against `config.max_auth_attempts`.\n\n#### Reachability trace verified\n\n1. Entry point: exported server API `server::run_stream` in `russh/src/server/mod.rs:1049`.\n2. Session run loop in `russh/src/server/session.rs` processes incoming packets and calls `reply(...)` (`server/session.rs:725`).\n3. `reply` forwards encrypted packets to `session.server_read_encrypted(...)` (`server/mod.rs:1221`).\n4. `server_read_encrypted` routes `USERAUTH_REQUEST` to `enc.server_read_auth_request(...)` (`server/encrypted.rs:89`).\n5. On each request, `self.common.auth_attempts += 1` executes (`server/encrypted.rs:98`).\n6. No comparison against `self.common.config.max_auth_attempts` is present in this runtime flow.\n\n### PoC\n\n#### Reproduction steps and observed output\n\nI did not run a full server process in this environment because Rust tooling is unavailable. I verified the issue from source and command output on the audited tree.\n\n1. Show where `max_auth_attempts` appears:\n\n```bash\nrtk rg -n \"max_auth_attempts\" .scratch/russh/russh/src/server/mod.rs .scratch/russh/russh/src/server/encrypted.rs .scratch/russh/russh/src/server/session.rs\n```\n\nObserved:\n\n```text\n.scratch/russh/russh/src/server/mod.rs:91:    pub max_auth_attempts: usize,\n.scratch/russh/russh/src/server/mod.rs:121:            max_auth_attempts: 10,\n.scratch/russh/russh/src/server/mod.rs:148:            .field(\"max_auth_attempts\", \u0026self.max_auth_attempts)\n```\n\n2. Show runtime auth-attempt handling:\n\n```bash\nrtk rg -n \"auth_attempts == 0|auth_attempts \\\\+= 1\" .scratch/russh/russh/src/server/encrypted.rs\n```\n\nObserved:\n\n```text\n53:        let initial_none_rejection_wait_until = if self.common.auth_attempts == 0 {\n98:                self.common.auth_attempts += 1;\n```\n\n3. Show production entrypoint-to-auth path references:\n\n```bash\nrtk rg -n \"pub async fn run_stream|match reply\\\\(|server_read_encrypted\\\\(|server_read_auth_request\\\\(\" .scratch/russh/russh/src/server/mod.rs .scratch/russh/russh/src/server/session.rs .scratch/russh/russh/src/server/encrypted.rs\n```\n\nObserved:\n\n```text\n.scratch/russh/russh/src/server/encrypted.rs:89:                enc.server_read_auth_request(\n.scratch/russh/russh/src/server/session.rs:725:                            match reply(\u0026mut self, \u0026mut handler, \u0026mut pkt).await {\n.scratch/russh/russh/src/server/mod.rs:1049:pub async fn run_stream\u003cH, R\u003e(\n.scratch/russh/russh/src/server/mod.rs:1221:    session.server_read_encrypted(handler, pkt).await\n```\n\n4. Toolchain check:\n\n```bash\ncargo --version\n```\n\nObserved:\n\n```text\n/bin/bash: line 1: cargo: command not found\n```\n\n### Impact\n\n#### Attacker model\n\n- Attacker: unauthenticated remote client with TCP reachability to a russh-backed SSH service.\n- Preconditions: deployer expects `server::Config.max_auth_attempts` to cap attempts.\n- Impact: repeated `USERAUTH_REQUEST` attempts continue for a single connection beyond configured limit, increasing online guessing opportunity and backend auth workload.\n\n### Suggested fix\n\nEnforce `max_auth_attempts` in the `USERAUTH_REQUEST` branch before invoking auth-method handlers, and fail closed once threshold is reached.\n\nConcrete patch direction in `russh/src/server/encrypted.rs`:\n\n```rust\nif self.common.config.max_auth_attempts \u003e 0\n    \u0026\u0026 self.common.auth_attempts \u003e= self.common.config.max_auth_attempts\n{\n    self.common.disconnect(\n        Disconnect::NoMoreAuthMethodsAvailable,\n        \"Too many authentication attempts\",\n        \"\",\n    )?;\n    return Ok(());\n}\n```\n\n### How it was found and a note on tooling\n\nThe researcher synthesized three lens outputs, then revalidated each claim against current `main`: source presence and commit history, advisory overlap checks in both GitHub advisories and OSV, entrypoint-to-sink reachability, attacker-model realism, and execution-claim integrity. The researcher used `gh`, `git`, `rg`, and direct source inspection under `.scratch/russh`. Because Rust tooling is unavailable in this worker, this report is intentionally marked `source-only`.\n\nAI assistance was used while investigating this and while drafting this report. The finding was verified by reading the cited code at HEAD. The vulnerability was not executed it, and that limit is stated plainly above rather than left implied.\n\nCredits: arpitjain099.",
  "id": "GHSA-g6xm-f9xp-qq35",
  "modified": "2026-09-30T23:26:17Z",
  "published": "2026-09-30T23:26:17Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/Eugeny/russh/security/advisories/GHSA-g6xm-f9xp-qq35"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-102825"
    },
    {
      "type": "WEB",
      "url": "https://github.com/Eugeny/russh/commit/f8fd0b11a393364dc7f01a182482d86adafdd653"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/Eugeny/russh"
    },
    {
      "type": "WEB",
      "url": "https://github.com/Eugeny/russh/releases/tag/v0.62.6"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Russh: Configured server auth-attempt cap is not enforced in the USERAUTH_REQUEST runtime path"
}

GHSA-G774-49MH-XQJP

Vulnerability from github – Published: 2026-01-23 00:31 – Updated: 2026-01-23 00:31
VLAI
Details

This vulnerability arises because there are no limitations on the number of authentication attempts a user can make. An attacker can exploit this weakness by continuously sending authentication requests, leading to a denial-of-service (DoS) condition. This can overwhelm the authentication system, rendering it unavailable to legitimate users and potentially causing service disruption. This can also allow attackers to conduct brute-force attacks to gain unauthorized access.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2025-53968"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-307"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-01-22T23:15:49Z",
    "severity": "HIGH"
  },
  "details": "This vulnerability arises because there are no limitations on the number\n of authentication attempts a user can make. An attacker can exploit \nthis weakness by continuously sending authentication requests, leading \nto a denial-of-service (DoS) condition. This can overwhelm the \nauthentication system, rendering it unavailable to legitimate users and \npotentially causing service disruption. This can also allow attackers to\n conduct brute-force attacks to gain unauthorized access.",
  "id": "GHSA-g774-49mh-xqjp",
  "modified": "2026-01-23T00:31:17Z",
  "published": "2026-01-23T00:31:17Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-53968"
    },
    {
      "type": "WEB",
      "url": "https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-022-08.json"
    },
    {
      "type": "WEB",
      "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-26-022-08"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-G7H3-M79W-RCRP

Vulnerability from github – Published: 2023-04-16 03:30 – Updated: 2024-04-04 03:29
VLAI
Details

ENTAB ERP 1.0 allows attackers to discover users' full names via a brute force attack with a series of student usernames such as s10000 through s20000. There is no rate limiting.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2022-30076"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-307"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2023-04-16T03:15:00Z",
    "severity": "MODERATE"
  },
  "details": "ENTAB ERP 1.0 allows attackers to discover users\u0027 full names via a brute force attack with a series of student usernames such as s10000 through s20000. There is no rate limiting.",
  "id": "GHSA-g7h3-m79w-rcrp",
  "modified": "2024-04-04T03:29:50Z",
  "published": "2023-04-16T03:30:25Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-30076"
    },
    {
      "type": "WEB",
      "url": "http://packetstormsecurity.com/files/171777/ENTAB-ERP-1.0-Information-Disclosure.html"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-G82J-WPRP-Q9Q9

Vulnerability from github – Published: 2024-05-14 18:30 – Updated: 2025-02-12 18:31
VLAI
Details

KioWare for Windows (versions all through 8.35) allows to brute force the PIN number, which protects the application from being closed, as there are no mechanisms preventing a user from excessively guessing the number.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-3461"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-307"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2024-05-14T15:41:13Z",
    "severity": "MODERATE"
  },
  "details": "KioWare for Windows (versions all through 8.35)\u00a0allows to brute force the PIN number, which protects the application from being closed, as there are no mechanisms preventing a user from excessively guessing the number.",
  "id": "GHSA-g82j-wprp-q9q9",
  "modified": "2025-02-12T18:31:28Z",
  "published": "2024-05-14T18:30:52Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3461"
    },
    {
      "type": "WEB",
      "url": "https://cert.pl/en/posts/2024/04/CVE-2024-3459"
    },
    {
      "type": "WEB",
      "url": "https://cert.pl/posts/2024/04/CVE-2024-3459"
    },
    {
      "type": "WEB",
      "url": "https://www.kioware.com"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-G889-QRP9-QWXW

Vulnerability from github – Published: 2025-10-31 00:30 – Updated: 2025-11-07 21:31
VLAI
Details

Nagios Fusion versions prior to 2024R2.1 contain a brute-force bypass in the Two-Factor Authentication (2FA) implementation. The application did not properly enforce rate limiting or account lockout for repeated failed 2FA verification attempts, allowing a remote attacker to repeatedly try second-factor codes for a targeted account. By abusing the lack of enforcement, an attacker could eventually successfully authenticate to accounts protected by 2FA.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2025-34249"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-307"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2025-10-30T22:15:47Z",
    "severity": "CRITICAL"
  },
  "details": "Nagios Fusion versions prior to 2024R2.1\u00a0contain a brute-force bypass in the Two-Factor Authentication (2FA) implementation. The application did not properly enforce rate limiting or account lockout for repeated failed 2FA verification attempts, allowing a remote attacker to repeatedly try second-factor codes for a targeted account. By abusing the lack of enforcement, an attacker could eventually successfully authenticate to accounts protected by 2FA.",
  "id": "GHSA-g889-qrp9-qwxw",
  "modified": "2025-11-07T21:31:19Z",
  "published": "2025-10-31T00:30:34Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-34249"
    },
    {
      "type": "WEB",
      "url": "https://www.nagios.com/changelog/nagios-fusion"
    },
    {
      "type": "WEB",
      "url": "https://www.nagios.com/products/security/#nagios-xi"
    },
    {
      "type": "WEB",
      "url": "https://www.vulncheck.com/advisories/nagios-fusion-2fa-brute-force-bypass"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
      "type": "CVSS_V4"
    }
  ]
}

GHSA-G92M-84FG-5M4G

Vulnerability from github – Published: 2026-08-24 15:31 – Updated: 2026-08-24 15:31
VLAI
Details

HCL Hive is affected by a missing rate limit which could allow an attacker unauthorized access via brute-force or credential stuffing attacks, or cause a denial of service.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2026-21755"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-307"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2026-08-24T15:16:37Z",
    "severity": "MODERATE"
  },
  "details": "HCL Hive is affected by a missing rate limit which could allow an attacker unauthorized access via brute-force or credential stuffing attacks, or cause a denial of service.",
  "id": "GHSA-g92m-84fg-5m4g",
  "modified": "2026-08-24T15:31:54Z",
  "published": "2026-08-24T15:31:54Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-21755"
    },
    {
      "type": "WEB",
      "url": "https://support.hcl-software.com/csm?id=kb_article\u0026sysparm_article=KB0131731"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
      "type": "CVSS_V3"
    }
  ]
}

Mitigation
Architecture and Design
  • Common protection mechanisms include:
  • Disconnecting the user after a small number of failed attempts
  • Implementing a timeout
  • Locking out a targeted account
  • Requiring a computational task on the user's part.
Mitigation MIT-4
Architecture and Design

Strategy: Libraries or Frameworks

  • Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482].
  • Consider using libraries with authentication capabilities such as OpenSSL or the ESAPI Authenticator. [REF-45]
CAPEC-16: Dictionary-based Password Attack

An attacker tries each of the words in a dictionary as passwords to gain access to the system via some user's account. If the password chosen by the user was a word within the dictionary, this attack will be successful (in the absence of other mitigations). This is a specific instance of the password brute forcing attack pattern.

Dictionary Attacks differ from similar attacks such as Password Spraying (CAPEC-565) and Credential Stuffing (CAPEC-600), since they leverage unknown username/password combinations and don't care about inducing account lockouts.

CAPEC-49: Password Brute Forcing

An adversary tries every possible value for a password until they succeed. A brute force attack, if feasible computationally, will always be successful because it will essentially go through all possible passwords given the alphabet used (lower case letters, upper case letters, numbers, symbols, etc.) and the maximum length of the password.

CAPEC-560: Use of Known Domain Credentials

An adversary guesses or obtains (i.e. steals or purchases) legitimate credentials (e.g. userID/password) to achieve authentication and to perform authorized actions under the guise of an authenticated user or service.

CAPEC-565: Password Spraying

In a Password Spraying attack, an adversary tries a small list (e.g. 3-5) of common or expected passwords, often matching the target's complexity policy, against a known list of user accounts to gain valid credentials. The adversary tries a particular password for each user account, before moving onto the next password in the list. This approach assists the adversary in remaining undetected by avoiding rapid or frequent account lockouts. The adversary may then reattempt the process with additional passwords, once enough time has passed to prevent inducing a lockout.

CAPEC-600: Credential Stuffing

An adversary tries known username/password combinations against different systems, applications, or services to gain additional authenticated access. Credential Stuffing attacks rely upon the fact that many users leverage the same username/password combination for multiple systems, applications, and services.

CAPEC-652: Use of Known Kerberos Credentials

An adversary obtains (i.e. steals or purchases) legitimate Kerberos credentials (e.g. Kerberos service account userID/password or Kerberos Tickets) with the goal of achieving authenticated access to additional systems, applications, or services within the domain.

CAPEC-653: Use of Known Operating System Credentials

An adversary guesses or obtains (i.e. steals or purchases) legitimate operating system credentials (e.g. userID/password) to achieve authentication and to perform authorized actions on the system, under the guise of an authenticated user or service. This applies to any Operating System.