Email sign-in one-time code could be brute-forced, allowing account takeover
Firezone's email sign-in one-time code had insufficient entropy and the verification endpoint enforced no per-code attempt limit, so a distributed attacker could brute-force a live code within its 15-minute window and sign in as another user. The issue has been resolved in the managed service; no action is required.