A lack of rate limiting in the One-Time Password (OTP)...
Moderate severity
Unreviewed
Published
Oct 20, 2025
to the GitHub Advisory Database
•
Updated Oct 21, 2025
Description
Published by the National Vulnerability Database
Oct 20, 2025
Published to the GitHub Advisory Database
Oct 20, 2025
Last updated
Oct 21, 2025
A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 allows attackers to bypass verification via a bruteforce attack.
References