VYPR

Punk::Plugin::TOTP

by Punk

CVEs (1)

  • CVE-2026-78655CriAug 25, 2026
    risk 0.59cvss 9.1epss 0.01

    Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts failures in the session. The POST handler on challenge_path keeps the failure count as tries inside the…