CVE-2026-108162: Pingvin Share X before 1.22.0 Rate Limit Bypass via Spoofed X-Forwarded-For
Pingvin Share X before 1.22.0 contains a rate limit bypass vulnerability that allows unauthenticated remote attackers to evade per-IP throttling because backend/src/main.ts unconditionally trusts proxy headers. Attackers can rotate spoofed X-Forwarded-For values against /api/auth/signIn, /api/auth/signIn/totp, and /api/auth/resetPassword to brute-force passwords and TOTP codes and forge logged client IP addresses.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Pingvin Shareto a version that resolves this vulnerability.Fixed in 1.22.0
Event History
Frequently Asked Questions
Which deployments are exposed?
Pingvin Share X versions before 1.22.0 are exposed because the backend unconditionally trusts proxy headers. The affected authentication endpoints are /api/auth/signIn, /api/auth/signIn/totp, and /api/auth/resetPassword.
What does an attacker need to exploit this?
An unauthenticated remote attacker can send requests with rotating spoofed X-Forwarded-For values. This defeats per-IP throttling and can enable brute-force attempts against passwords and TOTP codes.
How can defenders determine whether exploitation attempts occurred?
Review authentication and password-reset logs for suspicious or rapidly changing client IP addresses, since attackers can forge the logged client IP through X-Forwarded-For. Focus on activity involving the affected sign-in, TOTP, and reset-password endpoints.
What is the available fix?
Upgrade Pingvin Share X to version 1.22.0 or later. The vulnerability affects versions before 1.22.0.