CVE-2026-64619 Details
Description
FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateLimit class that allows unauthenticated attackers to circumvent request throttling by supplying attacker-controlled X-Real-IP and X-Forwarded-For headers without verification of trusted reverse proxy origin. Attackers can supply unique spoofed IP values on each request to enumerate all possible share codes and retrieve other users' files without authentication.
A rate limit bypass vulnerability has been identified in FileCodeBox versions prior to 2.4. This vulnerability resides in the IPRateLimit class, where the application fails to properly verify the origin of trusted reverse proxies. As a result, unauthenticated attackers can manipulate the X-Real-IP and X-Forwarded-For headers to evade request throttling. By sending unique spoofed IP addresses with each request, attackers can bypass rate limits, enumerate share codes, and access files shared by other users without authentication.
Users are advised to update to FileCodeBox version 2.5 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 20, 2026CISA-ADP
Assessed Jul 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/vastsa/FileCodeBox/commit/1b6d8e7277d3cfa34dc7a85803731d927b2147da | [email protected] | Source CodeVendor |
| https://github.com/vastsa/FileCodeBox/issues/479 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/vastsa/FileCodeBox/releases/tag/V2.4 | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/filecodebox-anti-bruteforce-rate-limit-bypass-via-spoofed-headers | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-348 | Use of Less Trusted Source | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| FileCodeBox | < 2.4 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 20, 2026 | CVE Modified | CISA-ADP |
| Jul 20, 2026 | New CVE Received | [email protected] |
Volerion