{"id":"CVE-2026-11922","summary":"Rate-limit Bypass in zenml-io/zenml","details":"A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass rate-limiting on the `POST /api/v1/login` and self password-change endpoints by rotating the `X-Forwarded-For` header. The rate limiter keys requests by `request.client.host`, which is derived from the `X-Forwarded-For` header when Uvicorn is launched with `--proxy-headers --forwarded-allow-ips *`. This configuration allows clients to control the value of `request.client.host`, effectively bypassing rate-limiting protections. This vulnerability leaves the affected endpoints open to unthrottled credential guessing attacks.","modified":"2026-07-27T03:56:36.616928553Z","published":"2026-07-24T03:27:39.188Z","database_specific":{"cna_assigner":"@huntr_ai","cwe_ids":["CWE-290"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/11xxx/CVE-2026-11922.json"},"references":[{"type":"WEB","url":"https://huntr.com/bounties/3cb8bf6a-ae55-4b38-8da3-601c666a210e"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/11xxx/CVE-2026-11922.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-11922"},{"type":"FIX","url":"https://github.com/zenml-io/zenml/commit/8a2214bdd63eb8200ce4719d82c6f0d935e922d1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zenml-io/zenml","events":[{"introduced":"dab417c864d0fb8a42ae0a6993698390bb0548d7"},{"fixed":"0f3a0533072395475df9be6d82b907a58f09be28"},{"fixed":"8a2214bdd63eb8200ce4719d82c6f0d935e922d1"}],"database_specific":{"extracted_events":[{"introduced":"0.57.0"},{"fixed":"0.94.2"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["0.94.5","0.94.4","0.94.3","0.94.2","0.94.1","0.94.0rc0","0.94.0","0.93.3","0.93.2","0.92.0","0.91.2","0.91.0","0.85.0","0.84.3","0.84.2","0.84.1","0.84.0","0.83.1","0.83.0","0.82.1","0.82.0","0.81.0","0.80.2","0.80.1","0.70.0","0.71.0","0.72.0","0.73.0","0.74.0","0.75.0","0.80.0","0.68.0","0.67.0","0.66.0","0.65.0","0.64.0","0.63.0","0.62.0","0.60.0","0.58.2","0.58.1","0.58.0","0.57.1","0.57.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-11922.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"}]}