logo

Database

Account lockout In payload

Description

Payload: Unauthenticated account-lockout denial of service

Impact

An unauthenticated attacker who knows an account’s email address or username could trigger Payload’s account lockout mechanism and prevent that user from signing in.

You are affected if:

    Using an affected Payload version with an auth-enabled collection that uses local authentication and account lockout.

Applications that do not use Payload local authentication are not affected.

Patches

Successful password resets now clear the account’s lockout state. The forgot-password flow also enforces a configurable minimum interval between reset emails, which defaults to 15 seconds.

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-O2XDR – Vulnerability | Fluid Attacks Database