- Status Closed
-
Assigned To
cbay - Private
Opened by adit616 - 04.10.2026
Last edited by cbay - 05.10.2026
FS#515 - No Rate Limit on /transfer/add/ — Invitation Spam Abuse (CVSS 5.3 Medium)
## Summary
POST /transfer/add/ (authenticated) has no rate limiting. Any free-tier user can spam transfer invitations to arbitrary email addresses, abusing alwaysdata's invitation email system for harassment.
Severity: Medium (CVSS 5.3) | CWE-307
CVSS: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
## Reproduce
1. Log in with any free account
2. Fire 30 concurrent POSTs to /transfer/add/ with email=victim@example.com 3. All 30 return HTTP 200 — no throttling triggered
## Evidence
- 30/30 HTTP 200 (parallel, ~1.55s total)
- No 429 even under concurrent load
## Impact
- Spam victim with unlimited alwaysdata-branded transfer invitation emails
- Abuse alwaysdata sending reputation for targeted harassment
## Remediation
Limit: 5-10 invitations/hour per user + 3/day per target email.
Researcher: adityahadipratama4@gmail.com Full PDF report (4 findings) attached via support ticket.
Loading...
Available keyboard shortcuts
- Alt + ⇧ Shift + l Login Dialog / Logout
- Alt + ⇧ Shift + a Add new task
- Alt + ⇧ Shift + m My searches
- Alt + ⇧ Shift + t focus taskid search
Tasklist
- o open selected task
- j move cursor down
- k move cursor up
Task Details
- n Next task
- p Previous task
- Alt + ⇧ Shift + e ↵ Enter Edit this task
- Alt + ⇧ Shift + w watch task
- Alt + ⇧ Shift + y Close Task
Task Editing
- Alt + ⇧ Shift + s save task
Hello,
There is a rate limit, and even if there weren't, it's not a vulnerability anyway.
Kind regards,
Cyril