Insufficient Granularity of Access Control in pixelfed/pixelfed


Reported on

Oct 9th 2021


There is no rate limit sent unlimited email victim or any email address.

Proof of Concept:

There is no rate limit return-password , attacker to send unlimited email to victim or any email address.


Attacker can sent unlimited email to any mail address .


Add 'throttle' => 60, to auth.php config or $this->middleware('throttle:3,1') to the forgot password controller construct.


We created a GitHub Issue asking the maintainers to create a 2 years ago
We have contacted a member of the pixelfed team and are waiting to hear back 2 years ago
pixelfed/pixelfed maintainer validated this vulnerability 2 years ago
HDVinnie has been awarded the disclosure bounty
The fix bounty is now up for grabs
pixelfed/pixelfed maintainer marked this as fixed with commit 2609c8 2 years ago
The fix bounty has been dropped
This vulnerability will not receive a CVE
to join this conversation