Sceawere
Vulnerability Detail
CVE-2026-108163UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Pingvin Share Rate Limit Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 3h ago
- Vendor
- smp46
- Product
- pingvin-share-x
- Attack Type
- Improper Restriction of Excessive Authentication Attempts
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Pingvin Share X before 1.22.0 contains an ineffective rate limiting vulnerability because throttler TTL values specified in seconds are interpreted as milliseconds. Unauthenticated attackers can send effectively unthrottled requests to /api/auth/signIn, /api/auth/signIn/totp and /api/auth/resetPassword to brute-force passwords and TOTP codes.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-10T14:16:37.530Z",
"pubdate": "2026-10-10T14:16:37.530Z",
"executiveSummary": "Pingvin Share X versions prior to 1.22.0 are susceptible to an ineffective rate limiting vulnerability stemming from a logic error in the throttler's time-to-live (TTL) configuration. By misinterpreting configured duration values—specifically treating seconds as milliseconds—the application fails to enforce meaningful request frequency constraints on sensitive authentication endpoints.\nThis flaw grants unauthenticated remote attackers the ability to bypass security throttles on /api/auth/signIn, /api/auth/signIn/totp, and /api/auth/resetPassword. Consequently, an attacker can conduct high-velocity brute-force or credential stuffing attacks against user passwords and time-based one-time passwords (TOTP). The lack of effective rate limiting significantly lowers the barrier for unauthorized account access, potentially leading to full account takeover. The vulnerability requires no prior authentication and is accessible over the network, posing a critical risk to the confidentiality and integrity of user credentials within the Pingvin Share environment.",
"technicalDetails": "The vulnerability resides in the application's request throttling mechanism, where the logic responsible for enforcing request frequency caps incorrectly parses TTL configurations. In the affected component, the backend expects a duration value in seconds; however, the throttler implementation interprets these inputs as milliseconds. This results in a functional time-out period that is 1,000 times shorter than intended, effectively rendering the rate limiting system inert under standard network conditions.\nThe attack flow targets specific API endpoints that lack the intended protective latency. An unauthenticated attacker leverages this bypass by directing automated requests at /api/auth/signIn, /api/auth/signIn/totp, and /api/auth/resetPassword. Because the throttler resets almost instantaneously due to the unit misconfiguration, the system fails to block or flag high-volume traffic from a single source IP or session. An attacker can iterate through large wordlists of passwords or attempt exhaustive enumeration of TOTP codes without triggering the expected security lockouts.\nExploitation is straightforward and does not require complex payloads or elevated privileges. By initiating a burst of requests to the aforementioned authentication routes, the attacker successfully traverses the authentication logic, which remains unshielded by the faulty throttler. The post-exploitation impact is severe, as the bypass facilitates the successful compromise of user accounts through brute-force methods. The vulnerability is persistent across all versions of Pingvin Share X prior to 1.22.0, as the underlying logic error applies globally to the application's authentication request processing pipeline.\nThe root cause is a type mismatch or configuration error where the expected temporal unit (seconds) is processed as milliseconds by the internal rate-limiting library or implementation. This creates a state of 'effective deactivation' where the overhead of the rate limiter is negligible to an attacker, allowing them to perform thousands of attempts within a timeframe that should have permitted only a few. There are no specific environmental requirements beyond network reachability to the application's API endpoints, and the attack can be fully automated using standard scriptable HTTP clients."
}