CVE-2026-44679: Tuist
Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.
Tuist is a virtual platform team for Swift app devs. Prior to 1.180.10, the forgot password flow allows an unauthenticated attacker to repeatedly trigger password reset emails for a known account without server-side throttling. In self-hosted deployments, this can be abused to send large volumes of unwanted email and consume downstream email delivery resources. This vulnerability is fixed in 1.180.10.
Affected products
- Tuist Tuist: before 1.180.10 (fixed in 1.180.10)
Published 2026-05-14. Last modified 2026-06-17.