VDB
Sign up
HIGH7.5

PYSEC-2026-835

No protection against brute-force attacks on login page

Quick fix

PYSEC-2026-835 — kiwitcms: upgrade to the fixed version with the command below.

pip install --upgrade 'kiwitcms>=12.0'

Details

### Impact Previous versions of Kiwi TCMS do not impose rate limits which makes it easier to attempt brute-force attacks against the login page.

### Patches Users should upgrade to v12.0 or later.

### Workarounds Users may install and configure a rate-limiting proxy in front of Kiwi TCMS. For example nginx.

### References [Disclosed by spyata](https://huntr.dev/bounties/2b1a9be9-45e9-490b-8de0-26a492e79795/)

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/kiwitcms
Introduced in: 0Fixed in: 12.0
Fixpip install --upgrade 'kiwitcms>=12.0'

References