Developer Exposes 12 Vulnerabilities in FastAPI Todo App After 176 Bots Bypass Protections
A Russian developer who started with a simple FastAPI todo list four months ago ended up running a multi-product platform and uncovering a dozen security issues after bots flooded the registration form.
The service at getdoday.ru grew to include a planner for schoolchildren, a Q&A module, a traffic-ticket trainer, and a tutor dashboard, all inside one 86,000-line monolith with 1,325 tests. Within two weeks the database showed 238 new accounts; only 62 confirmed their email. The remaining 176 were bots using disposable domains such as sdffsd.sdd and prweorwef.com.
Bots bypassed three protection layers
The original defenses were a honeypot field, a five-registrations-per-minute IP limit, and email confirmation. None worked. The rate limiter used an in-memory deque that was cleared on every deployment; with dozens of commits per day the counter effectively never existed. uvicorn was started with --forwarded-allow-ips='*', causing it to trust the leftmost IP supplied in the X-Forwarded-For header. An attacker could therefore rotate a fake address on every request and never hit the limit. Email verification set a timestamp but the column was never checked anywhere in the authorization logic.
Instead of adding hard email gates that would hurt real users behind school NATs, the developer implemented three lightweight checks: a signed timestamp proving the form was rendered at least a few seconds earlier, hourly registration counters stored in the database with separate per-subnet limits, and a DNS lookup confirming the mail domain actually exists.
Stored XSS via JSON-LD and an IDOR
During the subsequent full audit twelve additional vulnerabilities were found. Public Q&A pages rendered user-supplied question titles inside a JSON-LD script block using the safe filter. Because the HTML parser does not understand JSON, an attacker could close the script tag and inject executable code that exfiltrated the victim’s entire account export.
Another flaw allowed any logged-in user to read every task belonging to a project simply by supplying its UUID to the /api/tasks endpoint; membership checks existed only on the HTML page, not inside the service layer.
Other issues included an inability to invalidate sessions after password change and rate-limit bypasses on multiple endpoints. All findings were addressed with tests and the developer published the complete post-mortem on Habr.
Related articles
Cisco Patches 14 Vulnerabilities in NX-OS Software, Four Rated Critical
Cisco Systems has released security updates addressing 14 vulnerabilities in its Cisco NX-OS Software used in network devices. Four of the seven security advisories published on October 7, 2026, are rated Critical, while three are rated Medium. Several critical issues affect the Cisco Nexus 3000 Series and Nexus 9000 Series switches, impacting features such as NGOAM, MPLS OAM, and the NX-API management interface. Seven vulnerabilities received CVSSv3.1 base scores of 9.0 or higher, with multiple flaws enabling remote code execution as root or denial-of-service conditions. Specific CVEs including CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501 stem from input validation failures in the NGOAM feature and may require SRv6 or NV Overlay configurations to be exploitable. The advisories also cover control plane denial-of-service issues, Python sandbox escapes, and endpoint group contract bypasses in ACI mode.
HPE Networking ClearPass Policy Manager Hit by 28 Vulnerabilities Including 10 Rated Critical
Hewlett Packard Enterprise has disclosed 28 vulnerabilities in its HPE Networking ClearPass Policy Manager product and released security updates to address them. The issues span the web management interface, APIs, endpoint agents, and client software components. Ten of the flaws received a Critical severity rating. Notable issues include SQL injection, multiple authentication bypasses, unsafe deserialization leading to remote code execution, and path traversal. No public exploit code or active discussions were observed at the time the advisory was published on October 6, 2026. The company urges customers to apply the available patches promptly.
Attackers Exploit Critical Atlassian Data Center Flaw CVE-2026-21589 Hours After PoC Release
Exploitation attempts against CVE-2026-21589 began almost immediately after technical details and a Nuclei template were published. The vulnerability allows unauthenticated arbitrary file read in multiple Atlassian Data Center products and carries a CVSS v4.0 score of 9.3. In environments integrated with Crowd, attackers who obtain crowd.properties can extract plaintext credentials and escalate to administrator privileges via the Crowd API. The flaw stems from improper handling of double-colon sequences in a shared web resource library, enabling path traversal against plugin resource endpoints. Affected products include Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian urges immediate patching outside normal cycles and recommends WAF rules or Tomcat RewriteValve configurations to block traversal patterns. Organizations should also review access logs for double-decoded URLs containing .., /, \, or :: sequences.
LibreOffice and Apache OpenOffice Flaw Enables Remote Code Execution via Malicious Calc Tables Without Macro Warnings
Researchers have demonstrated an attack against LibreOffice and Apache OpenOffice users that executes arbitrary Java code simply by opening a malicious spreadsheet, without requiring macro permissions or triggering any security prompts. The vulnerability requires Java support to be enabled in the office suite and exploits legitimate features in the Calc component that automatically fetch data from external database sources. When a crafted document is opened, Calc loads a linked database file that references a malicious Java driver, allowing the attacker’s code to run inside the office process. LibreOffice has already patched the issue tracked as CVE-2026-63277 with the release of versions 26.2.5 and 26.8.0 on October 5, while Apache OpenOffice remains vulnerable up to version 4.1.16 under CVE-2026-59265 with a fix expected in 4.1.17. The attack chain works on both Windows and Linux and bypasses macro protections entirely because no user consent dialog appears. Although only a proof-of-concept exploit that launches the calculator has been published so far, the same technique can execute any Java payload. Users of OpenOffice are advised to disable Java or avoid untrusted files until the patch is available.