Rate Limiting Bypass in ZenML by ZenML IO
CVE-2026-11922

6.5MEDIUM

Key Information:

Vendor

Zenml-io

Vendor
CVE Published:
24 July 2026

What is CVE-2026-11922?

A vulnerability exists in ZenML versions 0.57.0 through 0.94.2 that allows attackers to bypass the rate-limiting mechanism designed to protect critical endpoints such as login and password change functionalities. By manipulating the X-Forwarded-For header, an attacker can control the value of request.client.host, circumventing intended rate-limiting protections. This exposes the affected endpoints to numerous unthrottled attempts to guess credentials, posing a significant security risk.

Affected Version(s)

zenml-io/zenml < 0.95.0

References

CVSS V3.0

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.