THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-73529 (MEDIUM 5.3) — Plainpad through 1.1.1, fixed in commit d3823fc, contains a missing rate limiting vulnerability that allows unauthenticated attackers to send unbounded login requests to the POST /v1/sessions endpoint due to dead code in App\Http\Kernel.php that is never instantiated under the La

[NVD] CVE-2026-73529 (MEDIUM 5.3) — Plainpad through 1.1.1, fixed in commit d3823fc, contains a missing rate limiting vulnerability that allows unauthenticated attackers to send unbounded login requests to the POST /v1/sessions endpoint due to dead code in App\Http\Kernel.php that is never instantiated under the La

mednvdPublished 2026-08-18

CVE-2026-73529 CVSS: 5.3 MEDIUM Published: 2026-08-18T20:17:28.577

Plainpad through 1.1.1, fixed in commit d3823fc, contains a missing rate limiting vulnerability that allows unauthenticated attackers to send unbounded login requests to the POST /v1/sessions endpoint due to dead code in App\Http\Kernel.php that is never instantiated under the Laravel 11+ skeleton, leaving the API throttle configu

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-73529