CVE-2026-11922: Zenml-Io Zenml-Io/zenml

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass rate-limiting on the `POST /api/v1/login` and self password-change endpoints by rotating the `X-Forwarded-For` header. The rate limiter keys requests by `request.client.host`, which is derived from the `X-Forwarded-For` header when Uvicorn is launched with `--proxy-headers --forwarded-allow-ips *`. This configuration allows clients to control the value of `request.client.host`, effectively bypassing rate-limiting protections. This vulnerability leaves the affected endpoints open to unthrottled credential guessing attacks.

Affected products

  • Zenml-Io Zenml-Io/zenml: before 0.95.0 (fixed in 0.95.0)

Published 2026-07-24. Last modified 2026-09-03.