Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33935

25
FAUCET Score

CVE-2026-33935 impacts MyTube versions prior to 1.8.72, allowing an unauthenticated attacker to cause a Denial of Service (DoS) by locking out legitimate users from password-based authentication. This vulnerability arises from a globally shared login attempt state across multiple public endpoints, enabling an attacker to repeatedly send invalid requests and progressively increase lockout durations up to 24 hours, which can be maintained indefinitely. Rated with a CVSSv4 score of 7.7 (High), the attack vector is network-based with low complexity, requiring no privileges or user interaction, and resulting in a high impact on availability. Although the method for exploitation is straightforward, there is currently no evidence of active exploitation, public exploit code, or significant community discussion, and its EPSS score is very low.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.8.72CPE matchmatch criteria
cpe:2.3:a:franklioxygen:mytube:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

7.7HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.54%
Probability of exploitation in next 30 days
EPSS Percentile
42.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0054 is in the 20th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / franklioxygen/MyTube/blob/941035909ee3f96a6f80f38acf70cbc3e66b5098/backend/src/services/loginAttemptService.ts
Product
github.com / franklioxygen/MyTube/commit/4d89b146b16d08f27d8fd3e0a9122b109335deb1
Patch
github.com / franklioxygen/MyTube/commit/752bc7f0ac83df8c881e6b6d5dd6f36bb274ee58
Patch
github.com / franklioxygen/MyTube/commit/dd7b4a611fcc5b25a569f379be9a503eb413b6aa
Patch
github.com / franklioxygen/MyTube/security/advisories/GHSA-6w95-qgc4-5jxf
ExploitVendor Advisory