CVE-2026-75773Disclosure

LOWCVSS 2.9 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in karakeep-app karakeep up to 0.32.0. The affected element is the function authorize of the file apps/web/server/auth.ts of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts. The attack may be performed from remote. This attack is characterized by high complexity. The exploitability is described as difficult. The exploit has been made public and could be used. Upgrading to version 0.33.0 is sufficient to fix this issue. The patch is identified as f7d042971d0d2bcc7119654830cf1eb93eabbf24. It is advisable to upgrade the affected component.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-307CWE-799

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-09-15)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-18: 1Mentions · 2026-09-15: 2Technical Details · 2026-08-18: 1Technical Details · 2026-09-15: 208-1809-15
Signal classification1 categories
Disclosure
3100.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-08-181
Disclosure1
2026-09-152
Disclosure2
Full discourse3 posts
  • Geng Yang@geng_zast
    Disclosure

    Karakeep's auth has a rate limiter. It just isn't on the login handler — and that's the whole bug. CVE-2026-75773: NextAuth credential login → validatePassword with no throttle. Brute-force runs unimpeded (bcrypt slows but doesn't stop it). https://t.co/k3t6EfAl3f

    Post summary

    The tweet discloses CVE-2026-75773, describing a missing rate limiter on Karakeep's NextAuth login handler that allows unimpeded brute-force attacks.

    1001077
    48 followersView on X
  • ZAST AI@zast_ai
    Disclosure

    ZAST found two CVEs in Karakeep ≤ 0.32.0: CVE-2026-75773 (login brute-force, CVSS 3.1 = 5.3) and CVE-2026-75774 (OAuth email-verification bypass, CVSS 3.1 = 4.8). 75773: no rate limiting on the credential login path. https://t.co/FuHWwx9b2R

    Post summary

    The tweet announces two new CVEs in Karakeep with technical details and a reference link, focusing on disclosure rather than exploitation or patching.

    1000070
    40 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-75773 Improper Restriction of Authentication Attempts in karakeep-app karakeep Up To 0.32.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-75773

    Post summary

    The entry announces CVE‑2026‑75773, describing it as an improper restriction of authentication attempts in karakeep-app up to version 0.32.0, with no PoC, exploit, or remediation details provided.

    0000092
    4.1K followersView on X

Explore more