Vulnerability GHSA-v5gf-vpjc-pc7w

Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
7 hours ago
October 07, 2026 at 08:29 PM UTC
Payload: Unauthenticated account-lockout denial of service
0.1.137 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33
0.1.137 - 3.89.0 and 4.0.0-canary.0 - 4.0.0-canary.33

Summary

Payload: Unauthenticated account-lockout denial of service

Details

Impact

An unauthenticated attacker who knows an account’s email address or username could trigger Payload’s account lockout mechanism and prevent that user from signing in.

You are affected if:

  • Using an affected Payload version with an auth-enabled collection that uses local authentication and account lockout.

Applications that do not use Payload local authentication are not affected.

Patches

Successful password resets now clear the account’s lockout state. The forgot-password flow also enforces a configurable minimum interval between reset emails, which defaults to 15 seconds.

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Impacted packages

Timeline

Published
7 hours ago
October 07, 2026 at 08:29 PM UTC
Fixed (3.90.0)
Unknown
Unknown
Fixed (4.0.0-canary.34)
Unknown
Unknown
Last Modified
7 hours ago
October 07, 2026 at 08:45 PM UTC