Rate Limiting Bypass in ZenML by ZenML IO
CVE-2026-11922
6.5MEDIUM
What is CVE-2026-11922?
A vulnerability exists in ZenML versions 0.57.0 through 0.94.2 that allows attackers to bypass the rate-limiting mechanism designed to protect critical endpoints such as login and password change functionalities. By manipulating the X-Forwarded-For header, an attacker can control the value of request.client.host, circumventing intended rate-limiting protections. This exposes the affected endpoints to numerous unthrottled attempts to guess credentials, posing a significant security risk.
Affected Version(s)
zenml-io/zenml < 0.95.0
