---
id: CVE-2023-0860
aliases:
  - GHSA-q9ww-gjpw-p9g6
  - PYSEC-2026-849
title: Improper Restriction of Excessive Authentication Attempts in modoboa
summary: Improper Restriction of Excessive Authentication Attempts in modoboa
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
vendor: modoboa
product: modoboa
ecosystem: pip
affected:
  - modoboa < 2.0.4
patched:
  - modoboa 2.0.4
published: '2023-02-16'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-q9ww-gjpw-p9g6'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-0860'
  - url: >-
      https://github.com/modoboa/modoboa-installer/commit/63d92b73f3da6971ae4e13d033d625773ac91085
  - url: 'https://github.com/modoboa/modoboa'
  - url: 'https://huntr.dev/bounties/64f3ab93-1357-4468-8ff4-52bbcec18cca'
tags:
  - osv
  - pip
  - exploit-available
epss: 0.00659
epssPercentile: 0.50134
ingestedAt: '2026-07-08T18:25:52.384Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/0xsu3ks/CVE-2023-0860'
  checkedAt: '2026-09-24T07:52:49.665Z'
exploitAvailable: true
---

## Overview

Improper Restriction of Excessive Authentication Attempts in GitHub repository modoboa/modoboa-installer prior to 2.0.4.

## Affected packages

- `modoboa < 2.0.4`

## Remediation

Upgrade to a patched release:

- `modoboa 2.0.4`
