Hall of Fame trophy
Back to Hall of Fame Contents

Contents / UserSearchBleed

User directory disclosure and regular-expression denial of service

GitHub advisories GHSA-88mv-h439-rj8j and GHSA-9846-cj96-6hv5, reported by Char0n1507 and Reload3d.

Authenticated clients could search all email addresses and receive administrator, disabled-account, authentication-provider, organization and team metadata. Raw search input also became a database regular expression in two DDP paths.

Fix: the general publication now returns only public identity fields. Both paths escape search text as literal input and are rate-limited. These changes affect what legitimate responses carry and how ordinary punctuation is interpreted, so searches are not logged as attacks. Fixed in the upcoming WeKan release on 2026-08-25.