What is CVE-2026-19898?
A vulnerability in the `requestHandler` function of the VMAuth component in VictoriaMetrics up to version 1.146.0 allows improper restriction of excessive authentication attempts. This could enable remote attackers to perform brute-force attacks. It is recommended to update VictoriaMetrics to the latest version to mitigate the issue.
Azərbaycanca: VictoriaMetrics-in 1.146.0 versiyasına qədər olan VMAuth komponentində `requestHandler` funksiyasında həddindən artıq autentifikasiya cəhdlərini məhdudlaşdırmayan zəiflik aşkarlanıb. Bu, uzaqdan hücumçuya brute-force hücumları həyata keçirməyə imkan verə bilər. Təsirə məruz qalmamaq üçün VictoriaMetrics-i ən son versiyaya yeniləmək tövsiyə olunur.
FAQ2
In which component of VictoriaMetrics was CVE-2026-19898 discovered?
This vulnerability was discovered in the VMAuth component, specifically in the `requestHandler` function.
How can one protect against CVE-2026-19898?
It is recommended to update VictoriaMetrics to the latest version to protect against the vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.