Vulnerability GHSA-v5gf-vpjc-pc7w
Summary
Payload: Unauthenticated account-lockout denial of service
Details
Impact
An unauthenticated attacker who knows an account’s email address or username could trigger Payload’s account lockout mechanism and prevent that user from signing in.
You are affected if:
- Using an affected Payload version with an auth-enabled collection that uses local authentication and account lockout.
Applications that do not use Payload local authentication are not affected.
Patches
Successful password resets now clear the account’s lockout state. The forgot-password flow also enforces a configurable minimum interval between reset emails, which defaults to 15 seconds.
Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.
Related Vulnerabilities
Other vulnerabilities affecting the same packages