← volver
CVE-2026-72584highCWE-367

fastschema - TOCTOU Race Condition Bypasses OTP Attempt Limit in Account Recovery

18Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 7.4
probabilidad de explotación
explotación observada
noninguna fuente lo reporta
A time-of-check/time-of-use (TOCTOU) race condition in fastschema through v0.15.1 allows an unauthenticated remote attacker to bypass the OTP attempt limit on the account recovery flow, enabling brute-force attacks on 6-digit OTP codes.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Productos afectados
fastschema · fastschema