
Karakeep's auth has a rate limiter. It just isn't on the login handler — and that's the whole bug. CVE-2026-75773: NextAuth credential login → validatePassword with no throttle. Brute-force runs unimpeded (bcrypt slows but doesn't stop it). https://t.co/k3t6EfAl3f
Post summary
The tweet discloses CVE-2026-75773, describing a missing rate limiter on Karakeep's NextAuth login handler that allows unimpeded brute-force attacks.


