VYPR

rodauth

by Rodauth

CVEs (5)

  • CVE-2026-82466HigAug 29, 2026
    risk 0.50cvss 8.7epss

    Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to authenticate as any other account. Attackers can exploit improper account resolution logic that falls back to session account identifiers instead of…

  • CVE-2026-82470MedAug 29, 2026
    risk 0.28cvss 5.4epss

    Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track the last accepted code timestamp. Attackers who observe a valid TOTP code can replay it during the drift window to bypass the second authentication factor.

  • CVE-2026-82469MedAug 29, 2026
    risk 0.28cvss 5.4epss

    Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT access tokens without requiring a refresh token. Attackers can present an access token to the refresh route via non-POST methods to obtain a new valid access token,…

  • CVE-2026-82468MedAug 29, 2026
    risk 0.24cvss 4.7epss

    Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types containing application/json substrings to bypass CSRF token validation and…

  • CVE-2026-82467MedAug 29, 2026
    risk 0.24cvss 4.7epss

    Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested_location, and two_factor_auth_return_to_requested_location features. Attackers can craft paths with leading double slashes that browsers resolve as…