Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-32gc-64m7-hj7v | 9Router has a Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 22 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Decolua
Decolua 9router |
|
| Vendors & Products |
Decolua
Decolua 9router |
Tue, 22 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | 9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper use the client-supplied X-9r-Real-Ip value as the bucket key in getClientIp, checkLock, and recordFail in src/lib/auth/loginLimiter.js for POST /api/auth/login. A remote unauthenticated attacker can rotate the header on every password guess so each request uses a new failed-attempt bucket and the five-attempt progressive lockout never returns HTTP 429. This permits unthrottled password guessing against the dashboard login and can lead to an administrative session if the password is recovered. This issue is fixed in version 0.5.6. | |
| Title | 9Router: Login Brute-Force Lockout Bypass via Spoofable X-9r-Real-Ip Header | |
| Weaknesses | CWE-307 CWE-807 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-22T17:23:12.515Z
Reserved: 2026-06-22T16:39:01.044Z
Link: CVE-2026-56682
Updated: 2026-09-22T17:23:06.512Z
Status : Deferred
Published: 2026-09-22T17:17:24.290
Modified: 2026-09-22T18:17:15.100
Link: CVE-2026-56682
No data.
OpenCVE Enrichment
Updated: 2026-09-22T17:45:17Z
Github GHSA