Junglewise Threat Intelligence

CVE-2026-78551: RansomLook authentication endpoint enumeration and DoS

CVE-2026-78551 · Severity: info · Published 2026-08-24

Technologies: RansomLook. Vendors: RansomLook.

Executive brief

RansomLook is a web application used for monitoring ransom threat actor activities. Its login system contained flaws that allowed attackers to discover valid usernames through timing analysis, attempt unlimited password guesses against known accounts, and potentially crash the application by overwhelming its worker processes with fake login attempts. This could lead to account takeover and service disruption.

Technical details

The vulnerability consists of multiple authentication weaknesses: (1) timing-based username enumeration—the application checked username existence before password verification, causing faster responses for invalid accounts and revealing valid usernames; (2) lack of rate limiting—the /login endpoint accepted unlimited failed attempts, enabling brute-force and credential-stuffing attacks; (3) CPU exhaustion DoS—each login attempt invokes an expensive password key-derivation function, allowing attackers to exhaust Gunicorn worker threads by sending high-rate requests. The attack requires only network access to the login endpoint and no authentication. Fixes include constant-time dummy-hash verification for nonexistent users, per-IP rate limiting via Redis (5 failures in 5 minutes = 1-hour block), and trusted X-Forwarded-For header handling in the reverse proxy.

Affected products

  • RansomLook RansomLook

Timeline

  • 2026-08-24: disclosed

Related threats