Browse all 6 CVE security advisories affecting Sync-in. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-58272 | Sync-in Server has Username/Login Enumeration via Timing Side-Channel on POST /api/auth/login (incomplete fix of the prior timing-attack advisory) — server CWE-208 | 5.3 | Medium | 2026-09-21 |
| CVE-2026-58270 | Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters` — server CWE-1333 | 6.5 | Medium | 2026-09-21 |
| CVE-2026-58269 | Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token` — server CWE-288 | 8.1 | High | 2026-09-21 |
| CVE-2026-58271 | @sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register` — server CWE-307 | 6.8 | Medium | 2026-09-21 |
| CVE-2026-47684 | Sync-in Server: SSRF protection bypass via IPv4-mapped IPv6 addresses in regExpPrivateIP — server CWE-918 | 7.7 | High | 2026-06-16 |
| CVE-2026-41161 | Username Enumeration via Timing Attack — server CWE-208 | 5.3AI | Medium AI | 2026-05-08 |
This page lists every published CVE security advisory associated with Sync-in. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.