CVE-2026-33935Disclosure(franklioxygen / mytube)

LOWCVSS 7.5 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch franklioxygen mytube systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.72, an unauthenticated attacker can lock out administrator and visitor accounts from password-based authentication by triggering failed login attempts. The application exposes three password verification endpoints, all of which are publicly accessible. All three endpoints share a single file-backed login attempt state stored in `login-attempts.json`. When any endpoint records a failed authentication attempt via `recordFailedAttempt()`, the shared login attempt state is updated, increasing the `failedAttempts` counter and adjusting the associated timestamps and cooldown values. Before verifying a password, each endpoint calls `canAttemptLogin()`. This function checks the shared JSON file to determine whether a cooldown period is active. If the cooldown has not expired, the request is rejected before the password is validated. Because the failed attempt counter and cooldown timer are globally shared, failed authentication attempts against any endpoint affect all other endpoints. An attacker can exploit this by repeatedly sending invalid authentication requests to any of these endpoints, incrementing the shared counter and waiting for the cooldown period between attempts. By doing so, the attacker can progressively increase the lockout duration until it reaches 24 hours, effectively preventing legitimate users from authenticating. Once the maximum lockout is reached, the attacker can maintain the denial of service indefinitely by waiting for the cooldown to expire and sending another failed attempt, which immediately triggers another 24-hour lockout if no successful login occurred in the meantime. Version 1.8.72 fixes the vulnerability.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-307

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mytube

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 4 total mentions across 1 day

Affected systems

Products
mytube

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-27: 4Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-27: 303-27
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • Fernando Karl@fernandokarl
    Patch

    🚨 Attention MyTube users! A vulnerability allows attackers to escalate login failures, causing Denial of Service for up to 24 hours. Update to version 1.8.72 now to secure your system! Don't wait! ⏳ #Cybersecurity #Vulnerability #MyTube https://www.tenable.com/cve/CVE-2026-33935

    Post summary

    CVE‑2026‑33935 causes a denial‑of‑service through escalated login failures; users are urged to update to MyTube version 1.8.72 to mitigate the risk.

    0000033
    258 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33935 MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.72, an unauthenticated attacker can lock out administrator and visitor a… https://www.cve.org/CVERecord?id=CVE-2026-33935

    Post summary

    The message announces CVE‑2026‑33935, stating that before v1.8.72 MyTube allows an unauthenticated attacker to lock out administrators and visitors; no PoC, exploit code, patch, or evidence of active exploitation is mentioned.

    00000106
    56.9K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-33935 📊 Severity: 7.7 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33935 #CVE-2026-33935 #CVE #High #CyberSecurity #InfoSec https://t.co/glRHWfFWzP

    Post summary

    The post announces a new CVE-2026-33935 with a high severity rating and a reference to NVD, but provides no details on exploitation, patching, or technical specifics.

    0000031
    123 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33935 - MyTube has Unauthenticated Account Lockout via Shared Login Attempt State Intel Report: https://ift.tt/CdT5Y9z

    Post summary

    A new vulnerability, CVE-2026-33935, was disclosed affecting MyTube, leading to unauthenticated account lockout through a shared login attempt state.

    0000044
    284 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfranklioxygenmytube---

Explore more