CVE-2026-87816: Pglombardo Passwordpusher

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

PasswordPusher before 2.11.1 contains a time-of-check-to-time-of-use race condition in view limit enforcement that allows unauthenticated attackers to bypass expire_after_views limits. Attackers can send concurrent requests to the show endpoint to access one-time secrets multiple times before the view count is incremented and the push expires.

Affected products

  • Pglombardo Passwordpusher: before 2.11.1 (fixed in 2.11.1)

Published 2026-09-09. Last modified 2026-09-10.