Tuist is a virtual platform team for Swift app devs. Prior to 1.180.10, the forgot password flow allows an unauthenticated attacker to repeatedly trigger password reset emails for a known account without server-side throttling. In self-hosted deployments, this can be abused to send large volumes of unwanted email and consume downstream email delivery resources. This vulnerability is fixed in 1.180.10.
Metrics
Affected Vendors & Products
References
History
Fri, 15 May 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tuist
Tuist tuist |
|
| Vendors & Products |
Tuist
Tuist tuist |
Thu, 14 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tuist is a virtual platform team for Swift app devs. Prior to 1.180.10, the forgot password flow allows an unauthenticated attacker to repeatedly trigger password reset emails for a known account without server-side throttling. In self-hosted deployments, this can be abused to send large volumes of unwanted email and consume downstream email delivery resources. This vulnerability is fixed in 1.180.10. | |
| Title | Tuist: Forgot password flow lacks throttling for reset email delivery | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-05-14T20:40:08.209Z
Updated: 2026-05-14T20:40:08.209Z
Reserved: 2026-05-07T16:20:08.660Z
Link: CVE-2026-44679
No data.
Status : Received
Published: 2026-05-14T21:16:47.780
Modified: 2026-05-14T21:16:47.780
Link: CVE-2026-44679
No data.