CVE-2025-57815
Python vulnerability analysis and mitigation

Overview

The Fides Admin UI login endpoint vulnerability (CVE-2025-57815) was discovered and disclosed on September 8, 2025. This security issue affects Fides, an open-source privacy engineering platform, in versions prior to 2.69.1. The vulnerability stems from the login endpoint relying on a general IP-based rate limit for all API traffic while lacking specific anti-automation controls designed to protect against brute-force attacks (GitHub Advisory).

Technical details

The vulnerability is classified as CWE-307 (Improper Restriction of Excessive Authentication Attempts). The system uses a configurable, system-wide rate limit to control traffic from any single IP address. However, because this single limit must be set high enough to accommodate endpoints that receive a large volume of legitimate traffic, it offers only weak protection for the login endpoint. The CVSS v3.1 base score is 6.5 (MEDIUM), with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N (NVD).

Impact

While password complexity requirements and the global rate limit make traditional brute-force attacks against single accounts difficult, the lack of authentication-specific protections exposes Fides to more targeted attacks. Attackers could potentially conduct credential testing attacks, such as credential stuffing or password spraying, which poses a risk to accounts with weak or previously compromised passwords. If successful, an attacker would gain full access to the compromised user's privileges within the Fides Admin UI (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in Fides version 2.69.1, which implements stricter rate limiting to authentication endpoints. For organizations with commercial Fides Enterprise licenses, a workaround is available through configuring Single Sign-On (SSO) via an OIDC provider (such as Azure, Google, or Okta). When OIDC SSO is enabled, username/password authentication can be disabled entirely, eliminating the attack vector. However, this functionality is not available for Fides Open Source users (GitHub Release, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-hmj8-5xmh-5573HIGH7.5
  • Python logoPython
  • libp2p
NoNoJul 24, 2026
GHSA-94p4-4cq8-9g67HIGH7.5
  • Python logoPython
  • gitpython
NoYesJul 24, 2026
GHSA-47w6-gwp4-w6vcHIGH7.1
  • Python logoPython
  • vantage6
NoNoJul 24, 2026
CVE-2026-59714HIGH7.1
  • Python logoPython
  • open-webui
NoYesJul 24, 2026
GHSA-464c-974j-9xm6LOW3.3
  • JavaScript logoJavaScript
  • software.amazon.awscdk:aws-cdk-lib
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management