What is CVE-2026-19897?
CVE-2026-19897 is a vulnerability found in mangroup dtale up to version 3.22.0, affecting the Login function in dtale/auth.py. It allows improper restriction of excessive authentication attempts, enabling remote brute-force attacks. Users are advised to upgrade to the latest version.
Azərbaycanca: CVE-2026-19897 mangroup dtale 3.22.0 versiyasına qədər olan versiyalarda Login endpointində aşkar edilmiş zəiflikdir. Bu boşluq ardıcıl autentifikasiya cəhdlərinin məhdudlaşdırılmamasına gətirib çıxarır ki, bu da uzaqdan brute-force hücumlarına şərait yaradır. İstifadəçilərə dtale proqramını ən son versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which versions of mangroup dtale are affected by CVE-2026-19897?
This vulnerability affects dtale versions up to 3.22.0.
What type of attack does this vulnerability enable?
Due to the lack of restriction on authentication attempts in the Login endpoint, it enables remote brute-force attacks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.