PT-2026-96821 · Vercel+1 · Next.Js+1

CVE-2026-56682

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions 9Router versions prior to 0.5.6
Description In deployments where requests reach Next.js without the sanitizing custom-server.js wrapper, the application uses the client-supplied X-9r-Real-Ip header as the bucket key for rate limiting. This occurs within the getClientIp(), checkLock(), and recordFail() functions in src/lib/auth/loginLimiter.js for the POST /api/auth/login endpoint. A remote unauthenticated attacker can bypass the progressive lockout mechanism by rotating the X-9r-Real-Ip header value with every request, ensuring each attempt is treated as a new bucket. This allows unthrottled password guessing against the dashboard login, which could lead to an administrative session if the password is recovered.
Recommendations Update to version 0.5.6. As a temporary mitigation, restrict access to the POST /api/auth/login endpoint or ensure the custom-server.js wrapper is correctly implemented to sanitize inbound headers.

Exploit

Fix

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56682
GHSA-32GC-64M7-HJ7V

Affected Products

9Router
Next.Js