Insufficient Rate Limiting Vulnerability in LightRAG by HKUDS
CVE-2026-85734
9.1CRITICAL
What is CVE-2026-85734?
The login endpoint in LightRAG allows an attacker to perform unlimited authentication attempts without any rate limiting or locking mechanism. This oversight enables potential credential recovery through rapid guesswork, thereby granting unauthorized access to sensitive documents, knowledge graphs, and administrative features. This vulnerability was remedied in version 1.5.5, reinforcing security measures for user accounts.
Affected Version(s)
LightRAG < 1.5.5
