ZAST.AI's engine flagged CVE-2026-19895 in OpenSourcePOS ≤ 3.4.2: login has no rate limiting, and CAPTCHA runs after the password check. That ordering turns credential correctness into an observable o

2: login has no rate limiting, and CAPTCHA runs after the password check. That ordering turns credential correctness into an observable oracle — a correct password returns a different error than a wrong one, so accounts get enumerated without solving a CAPTCHA.

2 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

ZAST.AI's engine flagged CVE-2026-19895 in OpenSourcePOS ≤ 3.4.2: login has no rate limiting, and CAPTCHA runs after the password check. That ordering turns credential correctness into an observable o

mastodon:infosec-exchangeother27d ago kagi ↗

ZAST.AI's engine flagged CVE-2026-19895 in OpenSourcePOS ≤ 3.4.2: login has no rate limiting, and CAPTCHA runs after the password check. That ordering turns credential correctness into an observable oracle — a correct password returns a different error than a wrong one, so accounts get enumerated without solving a CAPTCHA. /login is also CSRF-exempt. Two small gaps, one free credential-enumeration

ZAST.AI identified and verified CVE-2026-19895 in OpenSourcePOS ≤ 3.4.2 (CVSS 3.1 = 5.3). The login endpoint lacks brute-force protection, and its CAPTCHA validation order creates a credential-validit

mastodon:infosec-exchangeother27d ago kagi ↗

ZAST.AI identified and verified CVE-2026-19895 in OpenSourcePOS ≤ 3.4.2 (CVSS 3.1 = 5.3). The login endpoint lacks brute-force protection, and its CAPTCHA validation order creates a credential-validity oracle. Our AI agent uncovered this from source code; the report includes a PoC and remediation steps. Full report: https:// blog.zast.ai/vulnerability%20r esearch/web%20application%20security/cve-2