CVE-2026-21868 | FlagForgeCTF flagForge up to 2.3.2 API Endpoint /api/user/ Username redos (GHSA-949h-9824-xmcx / CNNVD-202601-1576)
A vulnerability, which was classified as problematic, was found in FlagForgeCTF flagForge up to 2.3.2. The impacted element is an unknown function of the file /api/user/ of the component API Endpoint. Executing a manipulation of the argument Username can lead to inefficient regular expression complexity.
This vulnerability is handled as CVE-2026-21868. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.