Unrated severityOSV Advisory· Published Jan 19, 2026· Updated Jan 20, 2026
MyTube has Rate Limiting Bypass via X-Forwarded-For Header Spoofing
CVE-2026-23848
Description
MyTube is a self-hosted downloader and player for several video websites. Prior to version 1.7.71, a rate limiting bypass via X-Forwarded-For header spoofing allows unauthenticated attackers to bypass IP-based rate limiting on general API endpoints. Attackers can spoof client IPs by manipulating the X-Forwarded-For header, enabling unlimited requests to protected endpoints, including general API endpoints (enabling DoS) and other rate-limited functionality. Version 1.7.71 contains a patch for the issue.
Affected products
1- Range: v1.3.15, v1.3.16, v1.3.17, …
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/franklioxygen/MyTube/commit/bc057458804ae7ac70ea00605680512ed3d4257bmitrex_refsource_MISC
- github.com/franklioxygen/MyTube/security/advisories/GHSA-59gr-529g-x45hmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.