CVE-2026-108162: SMP46 Pingvin-Share-X
Medium severity, CVSS 6.5.
Pingvin Share X before 1.22.0 contains a rate limit bypass vulnerability that allows unauthenticated remote attackers to evade per-IP throttling because backend/src/main.ts unconditionally trusts proxy headers. Attackers can rotate spoofed X-Forwarded-For values against /api/auth/signIn, /api/auth/signIn/totp, and /api/auth/resetPassword to brute-force passwords and TOTP codes and forge logged client IP addresses.
Affected products
- SMP46 Pingvin-Share-X: before 1.22.0 (fixed in 1.22.0)
Published 2026-10-10. Last modified 2026-10-10.