CVE-2026-33621 addresses incomplete request-throttling protections for auth-checkable endpoints in PinchTab versions v0.7.7 through v0.8.4. This medium-severity vulnerability (CVSS 4.8) allows an unauthenticated network attacker to potentially brute-force authentication tokens due to missing or bypassed rate limiting. While not a direct authentication bypass, it weakens defense-in-depth, particularly if a weak token is configured and the API is externally exposed, though the default deployment is local-first. There is currently no evidence of active exploitation, public exploit code, or significant community discussion regarding this vulnerability. The issue was fully resolved in PinchTab v0.8.5.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.7.7, < 0.8.5CPE matchmatch criteria | cpe:2.3:a:pinchtab:pinchtab:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.