Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

AVideo API rate limit bypass via bot User-Agent header

AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass protected operations including login brute-force protection and perform unlimited password guessing attempts.

Disclosed 5 September 2026 · Record updated 13 September 2026

Impact

Attackers can bypass rate limiting on eight protected operations including login brute-force protection by sending requests with a bot User-Agent header.

Our coverage

No articles linked to this incident yet.

Sources

  1. github.comhttps://github.com/advisories/GHSA-54jr-hcr3-c8jp