Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/typemill/typemill |
|
Wed, 05 Aug 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Typemill
Typemill typemill |
|
| Vendors & Products |
Typemill
Typemill typemill |
Wed, 05 Aug 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login()) performs no rate-limiting, failed-attempt counting, or account lockout when captcha is disabled, which is the default configuration. An unauthenticated attacker can send unlimited password-guessing requests against any account, including administrators, with no throttling. The only attempt-counting/lockout logic present in the same file protects an optional secondary email-authcode step and does not apply to the primary password check. | |
| Title | typemill: No Rate Limiting on Login Endpoint Enables Unlimited Password Brute-Force | |
| Weaknesses | CWE-307 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: TuranSec
Published:
Updated: 2026-08-05T06:59:29.622Z
Reserved: 2026-08-05T06:56:15.799Z
Link: CVE-2026-71213
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-05T08:45:16Z
-
CWE-307
Improper Restriction of Excessive Authentication Attempts