CVE-2026-33879 Details
Description
Federated Learning and Interoperability Platform (FLIP) is an open-source platform for federated training and evaluation of medical imaging AI models across healthcare institutions. The FLIP login page in versions 0.1.1 and prior has no rate limiting or CAPTCHA, enabling brute-force and credential-stuffing attacks. FLIP users are external to the organization, increasing credential reuse risk. As of time of publication, it is unclear if a patch is available.
A vulnerability exists in the Federated Learning and Interoperability Platform (FLIP) login page, all versions prior to 0.1.1. The absence of rate limiting and CAPTCHA allows for brute-force and credential-stuffing attacks. This issue is particularly concerning as FLIP users are external to the organization, heightening the risk of credential reuse.
To address this vulnerability, FLIP users should enable AWS Cognito Advanced Security Features, which provide account takeover protection and adaptive authentication. Additionally, AWS WAF can be configured to rate limit login attempts. It is also recommended to implement rate limiting middleware in the FastAPI application.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/londonaicentre/FLIP/security/advisories/GHSA-p34f-488j-5cwv | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-307 | Improper Restriction of Excessive Authentication Attempts | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| aicentre federated learning and interoperability platform | < 0.1.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 8, 2026 | Initial Analysis | [email protected] |
| Mar 27, 2026 | New CVE Received | [email protected] |