PT-2026-57913 · Hedgedoc · Hedgedoc

CVE-2026-58488

·

Published

2026-07-13

·

Updated

2026-07-13

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions HedgeDoc versions prior to 1.11.0
Description HedgeDoc is an open source, real-time, collaborative, markdown notes application. The application allows attackers to bypass rate-limiting on the '/login' and '/register' endpoints by spoofing IP addresses. This occurs because the system prioritizes the cf-connecting-ip header—used by CloudFlare to identify the original client IP—over the actual source IP, even if the request does not originate from CloudFlare. Consequently, an attacker can send varying cf-connecting-ip headers to spam login attempts or create numerous arbitrary accounts.
Recommendations Update to version 1.11.0.

Exploit

Fix

Allocation of Resources Without Limits

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58488
GHSA-2F9F-W8XQ-276V

Affected Products

Hedgedoc