CVE-2026-69183 | monkeytypegame Monkeytype up to 26.26.0 Rate Limit Key Generator rate-limit.ts getKey/getKeyWithUid cf-connecting-ip/x-forwarded-for resource consumption
A vulnerability marked as problematic has been reported in monkeytypegame Monkeytype up to 26.26.0. Affected by this vulnerability is the function getKey/getKeyWithUid of the file backend/src/middlewares/rate-limit.ts of the component Rate Limit Key Generator. Performing a manipulation of the argument cf-connecting-ip/x-forwarded-for results in resource consumption.
This vulnerability is cataloged as CVE-2026-69183. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More