GHSA-9cgp-m28v-64xv was reported by crypto-nidh.
Unauthenticated DDP clients could repeatedly call password-recovery and email-verification methods, flooding mail delivery and allowing unbounded token attempts.
Fix: each address is limited to five forgot-password or reset-password calls and ten verification calls per minute. Only denied attempts are bounded and summarized as ResetBleed in Admin Panel → Problems. Fixed in the upcoming WeKan release on 2026-08-26.