PT-2026-96821 · Vercel+1 · Next.Js+1
CVE-2026-56682
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
9Router versions prior to 0.5.6
Description
In deployments where requests reach Next.js without the sanitizing
custom-server.js wrapper, the application uses the client-supplied X-9r-Real-Ip header as the bucket key for rate limiting. This occurs within the getClientIp(), checkLock(), and recordFail() functions in src/lib/auth/loginLimiter.js for the POST /api/auth/login endpoint. A remote unauthenticated attacker can bypass the progressive lockout mechanism by rotating the X-9r-Real-Ip header value with every request, ensuring each attempt is treated as a new bucket. This allows unthrottled password guessing against the dashboard login, which could lead to an administrative session if the password is recovered.Recommendations
Update to version 0.5.6.
As a temporary mitigation, restrict access to the
POST /api/auth/login endpoint or ensure the custom-server.js wrapper is correctly implemented to sanitize inbound headers.Exploit
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
9Router
Next.Js