Weak Rate Limiting in OpenReception Appointment Booking Software
CVE-2026-48082
What is CVE-2026-48082?
The OpenReception appointment booking software employs a SHA-256 proof-of-work mechanism to control the rate at which unauthenticated clients can establish connections and submit appointments. However, prior to version 1.0.6, the difficulty of this proof-of-work challenge was set too low, allowing modern hardware to bypass intended limitations within 200 milliseconds. Attackers could exploit this weakness to flood the booking system with requests, effectively negating any rate-limiting benefits. The issue arises from the ability to supply attacker-controlled parameters during the challenge, enabling them to generate unique throttle keys and evade limitations designed to control booking traffic. The release of version 1.0.6 addresses this vulnerability to enhance the security of the booking process.
Affected Version(s)
appointment-booking-software < 1.0.6
