๐Ÿ” CVE Alert

CVE-2026-44679

UNKNOWN 0.0

Tuist: Forgot password flow lacks throttling for reset email delivery

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Tuist is a virtual platform team for Swift app devs. Prior to 1.180.10, the forgot password flow allows an unauthenticated attacker to repeatedly trigger password reset emails for a known account without server-side throttling. In self-hosted deployments, this can be abused to send large volumes of unwanted email and consume downstream email delivery resources. This vulnerability is fixed in 1.180.10.

CWE CWE-770
Vendor tuist
Product tuist
Published May 14, 2026
Stay Ahead of the Next One

Get instant alerts for tuist tuist

Be the first to know when new unknown vulnerabilities affecting tuist tuist are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

tuist / tuist
< 1.180.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/tuist/tuist/security/advisories/GHSA-v7gr-7ww5-w4cx