CVE-2026-87816: Pglombardo Passwordpusher
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
PasswordPusher before 2.11.1 contains a time-of-check-to-time-of-use race condition in view limit enforcement that allows unauthenticated attackers to bypass expire_after_views limits. Attackers can send concurrent requests to the show endpoint to access one-time secrets multiple times before the view count is incremented and the push expires.
Affected products
- Pglombardo Passwordpusher: before 2.11.1 (fixed in 2.11.1)
Published 2026-09-09. Last modified 2026-09-10.