CVE-2026-108163: Pingvin Share X before 1.22.0 Ineffective Authentication Rate Limiting via Throttler TTL
Pingvin Share X before 1.22.0 contains an ineffective rate limiting vulnerability because throttler TTL values specified in seconds are interpreted as milliseconds. Unauthenticated attackers can send effectively unthrottled requests to /api/auth/signIn, /api/auth/signIn/totp and /api/auth/resetPassword to brute-force passwords and TOTP codes.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to brute-force attempts?
Pingvin Share X versions before 1.22.0 are affected. The exposed endpoints are /api/auth/signIn, /api/auth/signIn/totp, and /api/auth/resetPassword, and exploitation does not require authentication or user interaction.
What can an attacker attempt through the affected endpoints?
An unauthenticated attacker can make effectively unthrottled requests to brute-force account passwords and TOTP codes. The issue results from throttler TTL values expressed in seconds being interpreted as milliseconds.
What version resolves the issue?
Upgrade to Pingvin Share X 1.22.0 or later. The issue affects versions before 1.22.0.