CVE-2026-33935 impacts MyTube versions prior to 1.8.72, allowing an unauthenticated attacker to cause a Denial of Service (DoS) by locking out legitimate users from password-based authentication. This vulnerability arises from a globally shared login attempt state across multiple public endpoints, enabling an attacker to repeatedly send invalid requests and progressively increase lockout durations up to 24 hours, which can be maintained indefinitely. Rated with a CVSSv4 score of 7.7 (High), the attack vector is network-based with low complexity, requiring no privileges or user interaction, and resulting in a high impact on availability. Although the method for exploitation is straightforward, there is currently no evidence of active exploitation, public exploit code, or significant community discussion, and its EPSS score is very low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.72CPE matchmatch criteria | cpe:2.3:a:franklioxygen:mytube:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.