Rate Limiting Bypass Vulnerability in MyTube by Frankli Oxygen
CVE-2026-23848

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
19 January 2026

What is CVE-2026-23848?

MyTube, a self-hosted downloader and player for video websites, is susceptible to a rate limiting bypass vulnerability due to improper handling of the X-Forwarded-For header. This exploitation allows unauthorized attackers to spoof client IP addresses, evading IP-based rate limits on API endpoints. As a consequence, attackers may perform unlimited requests to restricted functionalities, threatening the stability and availability of the service. Users are advised to upgrade to version 1.7.71, which includes a fix for this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

MyTube < 1.7.71

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.