Junglewise Threat Intelligence

CVE-2026-44679: Tuist missing rate limiting in forgot password flow

CVE-2026-44679 · Severity: info · CVSS 6.9 · Published 2026-05-14

Executive brief

Tuist is a platform used by developers to manage and automate Swift application projects. A flaw in the 'forgot password' feature allows anyone to repeatedly trigger password reset emails for any known user account without restriction. For organizations hosting their own Tuist instance, this could lead to significant email delivery costs, exhaustion of email service quotas, and potential blacklisting of their mail servers due to high volumes of unwanted traffic.

Technical details

The vulnerability is classified as CWE-770 (Allocation of Resources Without Limits or Throttling) within the password recovery component. An unauthenticated attacker can programmatically submit password reset requests for a target email address because the server does not enforce rate limits or throttling on these requests. In self-hosted environments, this results in the exhaustion of downstream SMTP/email delivery resources and potential reputation damage to the sending domain. The issue is resolved in version 1.180.10 by implementing server-side throttling.

Affected products

  • Tuist Tuist < 1.180.10

Timeline

  • 2026-05-04: advisory: GitHub Security Advisory published
  • 2026-05-14: disclosed: CVE published to NVD

References