Vulnerability Description
AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force protection by issuing concurrent requests. Attackers can submit parallel credential attempts to exceed the documented 30-attempts-per-5-minutes login limit by an arbitrary factor determined only by their connection concurrency.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/WWBN/AVideo/security/advisories/GHSA-8jrm-qg5f-966w
- https://www.vulncheck.com/advisories/avideo-through-29.0-rate-limit-bypass-via-n
- https://github.com/WWBN/AVideo/security/advisories/GHSA-8jrm-qg5f-966w
FAQ
What is CVE-2026-92583?
CVE-2026-92583 is a vulnerability with a CVSS score of 6.5 (MEDIUM). AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login br...
How severe is CVE-2026-92583?
CVE-2026-92583 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-92583?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.