CVE-2022-2822Low· 3.7▾ SunlitOctoPrint does not have rate limiting on the login page
▾ Sunlit zone — Low / medium · no exploitation signal
impact 20.4 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.7%
0.7% → 0.8%
OctoPrint 1.7.3 and prior does not have rate limiting on the login page, making it possible for attackers to attempt brute force attacks. The severity of this issue is limited by OctoPrint normally running in a restricted LAN. The devel and maintenance branches of the repository have a fix that limits the rate of failed login attempts.
octoprint <= 1.7.3Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-23637Medium· 4.2OctoPrint Unverified Password Change via Access Control Settings
CVE-2026-23892Medium· 5.9OctoPrint has Timing Side-Channel Vulnerability in API Key Authentication
CVE-2025-48067Medium· 5.4OctoPrint vulnerable to possible file extraction via upload endpoints
CVE-2025-64187MediumOctoPrint vulnerable to XSS in Action Commands Notification and Prompt
CVE-2025-48879Medium· 6.5OctoPrint Vulnerable to Denial of Service through malformed HTTP request in OctoPrint
CVE-2025-58180High· 8.8OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload