Improper Restriction of Excessive Authentication Attempts in HedgeDoc - #VU127921
Published: February 2, 2025 / Updated: April 25, 2026
HedgeDoc
Detailed vulnerability description
The vulnerability allows a remote attacker to brute-force email and password combinations.
The vulnerability exists due to improper restriction of excessive authentication attempts in the local authentication login endpoint when handling repeated authentication requests. A remote attacker can send repeated login attempts to brute-force email and password combinations.
Only instances with the local account system enabled are vulnerable.