Medium severity6.5OSV Advisory· Published Jan 19, 2026· Updated Jun 17, 2026
CVE-2026-23848
CVE-2026-23848
Description
MyTube is a self-hosted downloader and player for several video websites. Prior to version 1.7.71, a rate limiting bypass via X-Forwarded-For header spoofing allows unauthenticated attackers to bypass IP-based rate limiting on general API endpoints. Attackers can spoof client IPs by manipulating the X-Forwarded-For header, enabling unlimited requests to protected endpoints, including general API endpoints (enabling DoS) and other rate-limited functionality. Version 1.7.71 contains a patch for the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3v1.3.15, v1.3.16, v1.3.17, …+ 1 more
- (no CPE)range: v1.3.15, v1.3.16, v1.3.17, …
- cpe:2.3:a:franklioxygen:mytube:*:*:*:*:*:*:*:*range: <1.7.71
Patches
Vulnerability mechanics
References
2- github.com/franklioxygen/MyTube/commit/bc057458804ae7ac70ea00605680512ed3d4257bnvdPatch
- github.com/franklioxygen/MyTube/security/advisories/GHSA-59gr-529g-x45hnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.