GHSA-v5gf-vpjc-pc7wMedium

Payload: Unauthenticated account-lockout denial of service

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

An unauthenticated attacker who knows an account’s email address or username could trigger Payload’s account lockout mechanism and prevent that user from signing in.

You are affected if:

  • Using an affected Payload version with an auth-enabled collection that uses local authentication and account lockout.

Applications that do not use Payload local authentication are not affected.

Patches

Successful password resets now clear the account’s lockout state. The forgot-password flow also enforces a configurable minimum interval between reset emails, which defaults to 15 seconds.

Users should upgrade Payload packages to >= 3.90.0 or >= 4.0.0-canary.34.

🎯 Affected products2

  • npm/payload:< 3.90.0
  • npm/payload:>= 4.0.0-canary.0, < 4.0.0-canary.34

🔗 References (5)