VYPR
Medium severity6.5OSV Advisory· Published Jan 19, 2026· Updated Jun 17, 2026

CVE-2026-23848

CVE-2026-23848

Description

MyTube is a self-hosted downloader and player for several video websites. Prior to version 1.7.71, a rate limiting bypass via X-Forwarded-For header spoofing allows unauthenticated attackers to bypass IP-based rate limiting on general API endpoints. Attackers can spoof client IPs by manipulating the X-Forwarded-For header, enabling unlimited requests to protected endpoints, including general API endpoints (enabling DoS) and other rate-limited functionality. Version 1.7.71 contains a patch for the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Franklioxygen/MytubeOSV2 versions
    v1.3.15, v1.3.16, v1.3.17, …+ 1 more
    • (no CPE)range: v1.3.15, v1.3.16, v1.3.17, …
    • cpe:2.3:a:franklioxygen:mytube:*:*:*:*:*:*:*:*range: <1.7.71
  • MyTube/MyTubellm-fuzzy
    Range: <1.7.71

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.