CVE-2026-56682: CWE-307: Improper Restriction of Excessive Authentication Attempts in decolua 9router
9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper use the client-supplied X-9r-Real-Ip value as the bucket key in getClientIp, checkLock, and recordFail in src/lib/auth/loginLimiter.js for POST /api/auth/login. A remote unauthenticated attacker can rotate the header on every password guess so each request uses a new failed-attempt bucket and the five-attempt progressive lockout never returns HTTP 429. This permits unthrottled password guessing against the dashboard login and can lead to an administrative session if the password is recovered. This issue is fixed in version 0.5.6.
AI Analysis
Technical Summary
The vulnerability in decolua 9router (before version 0.5.6) arises because the login rate limiting mechanism uses the client-supplied X-9r-Real-Ip header as the bucket key for tracking failed login attempts. Attackers can manipulate this header on each login attempt, causing each request to be treated as a new client and thus bypassing the five-attempt progressive lockout that would normally return HTTP 429 responses. This flaw permits unlimited password guessing attempts against the dashboard login endpoint (/api/auth/login), potentially leading to administrative access if the password is compromised. The vulnerability is classified under CWE-307 (Improper Restriction of Excessive Authentication Attempts) and CWE-807. The issue has been addressed and fixed in version 0.5.6 of 9router.
Potential Impact
An unauthenticated remote attacker can bypass the intended login attempt rate limiting by rotating the X-9r-Real-Ip header, enabling unlimited password guessing attempts against the dashboard login. This can lead to compromise of administrative credentials if the password is guessed successfully. The confidentiality impact is low (limited to potential credential compromise), with no direct integrity or availability impact reported.
Mitigation Recommendations
Upgrade to decolua 9router version 0.5.6 or later, where this vulnerability is fixed. No other mitigations are indicated by the vendor advisory. Patch status is confirmed fixed in 0.5.6.
CVE-2026-56682: CWE-307: Improper Restriction of Excessive Authentication Attempts in decolua 9router
Description
9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper use the client-supplied X-9r-Real-Ip value as the bucket key in getClientIp, checkLock, and recordFail in src/lib/auth/loginLimiter.js for POST /api/auth/login. A remote unauthenticated attacker can rotate the header on every password guess so each request uses a new failed-attempt bucket and the five-attempt progressive lockout never returns HTTP 429. This permits unthrottled password guessing against the dashboard login and can lead to an administrative session if the password is recovered. This issue is fixed in version 0.5.6.
CVSS v3.1
Score 5.3medium
Affected software
decolua
9router
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in decolua 9router (before version 0.5.6) arises because the login rate limiting mechanism uses the client-supplied X-9r-Real-Ip header as the bucket key for tracking failed login attempts. Attackers can manipulate this header on each login attempt, causing each request to be treated as a new client and thus bypassing the five-attempt progressive lockout that would normally return HTTP 429 responses. This flaw permits unlimited password guessing attempts against the dashboard login endpoint (/api/auth/login), potentially leading to administrative access if the password is compromised. The vulnerability is classified under CWE-307 (Improper Restriction of Excessive Authentication Attempts) and CWE-807. The issue has been addressed and fixed in version 0.5.6 of 9router.
Potential Impact
An unauthenticated remote attacker can bypass the intended login attempt rate limiting by rotating the X-9r-Real-Ip header, enabling unlimited password guessing attempts against the dashboard login. This can lead to compromise of administrative credentials if the password is guessed successfully. The confidentiality impact is low (limited to potential credential compromise), with no direct integrity or availability impact reported.
Mitigation Recommendations
Upgrade to decolua 9router version 0.5.6 or later, where this vulnerability is fixed. No other mitigations are indicated by the vendor advisory. Patch status is confirmed fixed in 0.5.6.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-22T16:39:01.044Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab2add8f7a7c541066e1173
Added to database: 09/22/2026, 16:33:28 UTC
Last enriched: 09/22/2026, 16:48:04 UTC
Last updated: 09/23/2026, 01:58:06 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.