PT-2026-57913 · Hedgedoc · Hedgedoc
CVE-2026-58488
·
Published
2026-07-13
·
Updated
2026-07-13
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
HedgeDoc versions prior to 1.11.0
Description
HedgeDoc is an open source, real-time, collaborative, markdown notes application. The application allows attackers to bypass rate-limiting on the '/login' and '/register' endpoints by spoofing IP addresses. This occurs because the system prioritizes the
cf-connecting-ip header—used by CloudFlare to identify the original client IP—over the actual source IP, even if the request does not originate from CloudFlare. Consequently, an attacker can send varying cf-connecting-ip headers to spam login attempts or create numerous arbitrary accounts.Recommendations
Update to version 1.11.0.
Exploit
Fix
Allocation of Resources Without Limits
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hedgedoc