PT-2025-42225 · Unknown · Signinghub

Published

2025-10-14

·

Updated

2025-10-27

·

CVE-2025-56219

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions SigningHub version 8.6.8
Description An issue exists in SigningHub version 8.6.8 where incorrect access control allows attackers to create an unlimited number of user accounts. The absence of rate limiting enables attackers to exhaust system resources, potentially leading to a Denial of Service (DoS). The affected functionality involves adding packages via an API.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-56219

Affected Products

Signinghub