Race Condition Flaw in PasswordPusher Affects User Privacy
CVE-2026-87816
8.7HIGH
What is CVE-2026-87816?
A vulnerability in PasswordPusher before version 2.11.1 allows unauthenticated attackers to exploit a race condition related to view limit enforcement. This weakness enables attackers to bypass the 'expire_after_views' feature by rapidly sending concurrent requests to the show endpoint. As a result, they can repeatedly access one-time secrets before the view count has a chance to increment, compromising the intended security measures and allowing for potentially unauthorized information retrieval.
Affected Version(s)
PasswordPusher 0 < 2.11.1
PasswordPusher 2.11.1
