CVE-2026-107271
MEDIUM
6,9
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM
5,3
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: none
Availability: none
Description
AI Translation Available
Gophish through 0.12.1 contains a rate limit bypass vulnerability that allows unauthenticated attackers to evade /login throttling by spoofing X-Forwarded-For or X-Real-IP headers. Attackers can send a different forwarded address per request so the limiter keyed on rewritten RemoteAddr never triggers, enabling unlimited password guessing and credential stuffing.
348
Use of Less Trusted Source
DraftCommon Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism
Gain Privileges Or Assume Identity
Applicable Platforms
All platforms may be affected
https://blog.ostorlab.co/gophish-0121-manual-review-agentic-deep-scan.html
https://github.com/gophish/gophish
https://github.com/gophish/gophish/blob/b1648f0759c6d57ac989157c55d8b47c40254fe…
https://github.com/gophish/gophish/blob/b1648f0759c6d57ac989157c55d8b47c40254fe…
https://www.vulncheck.com/advisories/gophish-through-0.12.1-login-rate-limit-by…