PT-2026-99271 · Clawhub · Clawhub
CVE-2026-100600
·
Published
2026-09-26
·
Updated
2026-09-28
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ClawHub versions prior to 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650
Description
The application backend fails to bind anonymous HTTP API requests to a trusted caller identity, causing all direct anonymous requests to share a single default quota allowance. This allows an unauthenticated remote caller to exhaust the shared quota, resulting in a denial of service or degraded API access for other visitors. Furthermore, if the
TRUST FORWARDED IPS option is enabled without an authenticated edge or proxy, clients can manipulate forwarded IP headers to impersonate specific quota identities and bypass rate limiting.Recommendations
Update to revision 8c2de6c506bb4efabe3f0c2ffb8370b9e23d4650.
Disable the
TRUST FORWARDED IPS option if an authenticated edge or proxy is not in use.Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clawhub