User Impersonation Affecting zenml package, versions [,0.95.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.18% (8th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-ZENML-18600676
  • published9 Aug 2026
  • disclosed24 Jul 2026
  • creditUnknown

Introduced: 24 Jul 2026

NewCVE-2026-11922  (opens in a new tab)
CWE-290  (opens in a new tab)

How to fix?

Upgrade zenml to version 0.95.0 or higher.

Overview

zenml is a ZenML: Write production-ready ML code.

Affected versions of this package are vulnerable to User Impersonation in the POST /api/v1/login and self password-change endpoints when the rate limiter uses request.client.host derived from the X-Forwarded-For header. An attacker can circumvent request throttling by rotating the X-Forwarded-For header, enabling unthrottled credential guessing attacks. This is only exploitable if Uvicorn is launched with --proxy-headers --forwarded-allow-ips *.

CVSS Base Scores

version 4.0
version 3.1