THREAT OPS › Threat News › [NVD] CVE-2026-73529 (MEDIUM 5.3) — Plainpad through 1.1.1, fixed in commit d3823fc, contains a missing rate limiting vulnerability that allows unauthenticated attackers to send unbounded login requests to the POST /v1/sessions endpoint due to dead code in App\Http\Kernel.php that is never instantiated under the La
[NVD] CVE-2026-73529 (MEDIUM 5.3) — Plainpad through 1.1.1, fixed in commit d3823fc, contains a missing rate limiting vulnerability that allows unauthenticated attackers to send unbounded login requests to the POST /v1/sessions endpoint due to dead code in App\Http\Kernel.php that is never instantiated under the La
CVE-2026-73529 CVSS: 5.3 MEDIUM Published: 2026-08-18T20:17:28.577
Plainpad through 1.1.1, fixed in commit d3823fc, contains a missing rate limiting vulnerability that allows unauthenticated attackers to send unbounded login requests to the POST /v1/sessions endpoint due to dead code in App\Http\Kernel.php that is never instantiated under the Laravel 11+ skeleton, leaving the API throttle configu
Indicators of compromise
- CVE-2026-73529cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-73529