A lack of rate limiting in the login page of shiori v1.7.4 and below allows attackers to bypass authentication via a brute force attack.
References
| Link | Resource |
|---|---|
| https://github.com/go-shiori/shiori | Product |
| https://github.com/go-shiori/shiori/issues/1138 | Issue Tracking |
Configurations
History
No history.
Information
Published : 2026-01-09 21:16
Updated : 2026-01-22 21:39
NVD link : CVE-2025-60538
Mitre link : CVE-2025-60538
CVE.ORG link : CVE-2025-60538
JSON object : View
Products Affected
go-shiori
- shiori
CWE
CWE-290
Authentication Bypass by Spoofing
