← Volver a CVEs
CVE-2026-33879
CRITICAL9.8
Descripcion
Federated Learning and Interoperability Platform (FLIP) is an open-source platform for federated training and evaluation of medical imaging AI models across healthcare institutions. The FLIP login page in versions 0.1.1 and prior has no rate limiting or CAPTCHA, enabling brute-force and credential-stuffing attacks. FLIP users are external to the organization, increasing credential reuse risk. As of time of publication, it is unclear if a patch is available.
Detalles CVE
Puntuacion CVSS v3.19.8
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado3/27/2026
Ultima modificacion4/8/2026
Fuentenvd
Avistamientos honeypot0
Productos afectados
aicentre:federated_learning_and_interoperability_platform
Debilidades (CWE)
CWE-307
Referencias
https://github.com/londonaicentre/FLIP/security/advisories/GHSA-p34f-488j-5cwv(security-advisories@github.com)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.