OSS Password Pusher v2.14.3 — Security Release

An announcement from Password Pusher Pro.

Back to What's New
Fix

OSS Password Pusher v2.14.3 is out today with a security fix self-hosters should apply promptly.

Login throttle bypass — closed. The sign-in rate limiter could be bypassed under certain conditions, allowing more login attempts than the configured limit permits. The fix enforces throttling correctly on all sign-in paths. Thanks to @nullbenny for the responsible disclosure.

This release also hardens push-kind validation — unknown or malformed push kinds are now rejected cleanly rather than returning a 500 error.

To update, pull the latest Docker image (pglombardo/pwpush:latest) and restart. No configuration changes required.

Full release notes: github.com/pglombardo/PasswordPusher/releases/tag/v2.14.3

Available for all self-hosted OSS Password Pusher deployments.