CVE-2026-107271EPSS p5.4%
CVE-2026-107271CVE-2026-107271
Description
Gophish through 0.12.1 contains a rate limit bypass vulnerability that allows unauthenticated attackers to evade /login throttling by spoofing X-Forwarded-For or X-Real-IP headers. Attackers can send a different forwarded address per request so the limiter keyed on rewritten RemoteAddr never triggers, enabling unlimited password guessing and credential stuffing.
Scoring
| CVSS | 5.3 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
| EPSS | 0.17% probability of exploitation · percentile 5.4% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-07 |