PT-2026-99271 · Clawhub · Clawhub

CVE-2026-100600

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ClawHub versions prior to 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650
Description The application backend fails to bind anonymous HTTP API requests to a trusted caller identity, causing all direct anonymous requests to share a single default quota allowance. This allows an unauthenticated remote caller to exhaust the shared quota, resulting in a denial of service or degraded API access for other visitors. Furthermore, if the TRUST FORWARDED IPS option is enabled without an authenticated edge or proxy, clients can manipulate forwarded IP headers to impersonate specific quota identities and bypass rate limiting.
Recommendations Update to revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650. Disable the TRUST FORWARDED IPS option if an authenticated edge or proxy is not in use.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100600
GHSA-4C7Q-G7XF-5628

Affected Products

Clawhub