Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-32gc-64m7-hj7v | 9Router has a Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header |
Tue, 22 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Decolua
Decolua 9router |
|
| Vendors & Products |
Decolua
Decolua 9router |
Tue, 22 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | 9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper use the client-supplied X-9r-Real-Ip value as the bucket key in getClientIp, checkLock, and recordFail in src/lib/auth/loginLimiter.js for POST /api/auth/login. A remote unauthenticated attacker can rotate the header on every password guess so each request uses a new failed-attempt bucket and the five-attempt progressive lockout never returns HTTP 429. This permits unthrottled password guessing against the dashboard login and can lead to an administrative session if the password is recovered. This issue is fixed in version 0.5.6. | |
| Title | 9Router: Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header | |
| Weaknesses | CWE-307 CWE-807 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-22T17:23:12.515Z
Reserved: 2026-06-22T16:39:01.044Z
Link: CVE-2026-56682
No data.
Status : Deferred
Published: 2026-09-22T17:17:24.290
Modified: 2026-09-22T17:17:24.420
Link: CVE-2026-56682
No data.
OpenCVE Enrichment
Updated: 2026-09-22T17:30:18Z
Github GHSA