Executive brief
OpenReception is appointment booking software used by healthcare providers to manage patient scheduling. The software uses a proof-of-work challenge to rate-limit unauthenticated booking requests, but the difficulty is set too low (16 bits), solvable in under 200 milliseconds on commodity hardware. An attacker can bypass the rate-limiting mechanism and rapidly submit malicious booking requests or poison cryptographic credentials at scale.
Technical details
The bootstrap challenge endpoint at `/api/tenants/{id}/appointments/bootstrap-challenge` implements a SHA-256 proof-of-work mechanism with a hardcoded difficulty of 4 hex zeros (16 bits), intended to rate-limit unauthenticated clients. However, modern hardware solves this challenge in under 200 milliseconds using unoptimized code, providing negligible friction. Additionally, the throttle check uses attacker-controlled parameters (tunnelId, clientPublicKey, emailHash) to generate throttle keys, allowing an attacker to bypass per-binding rate-limiting by supplying fresh values on each request. An attacker can rapidly generate bootstrap challenges and solve them without meaningful server-side friction, enabling bulk abuse of the appointment booking flow and amplification of credential poisoning attacks. Version 1.0.6 increases the difficulty to 5 hex zeros; a more comprehensive fix should tune difficulty to a target solve time of 1–4 seconds on representative client hardware.
Affected products
- OpenReception appointment booking software prior to 1.0.6
Timeline
- 2026-05-20: disclosed: GHSA-hm9g-mh7x-657g published on GitHub security advisory
- 2026-08-06: advisory: CVE-2026-48082 published on NVD
- 2026-08-06: patched: Version 1.0.6 released with increased difficulty from 4 to 5 hex zeros