Rodauth 在 2.47.0 之前的版本中,在 、 和 功能中,未能正确验证协议相对的回跳路径。攻击者可以构造带有前导双斜杠( )的路径,浏览器会将其解析为协议相对 URL,从而在用户登录或密码确认后被重定向到攻击者控制的站点。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jeremyevans | rodauth | 0 ~ 2.47.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82466 | 8.7 HIGH | Rodauth before 2.46.0 Authentication Bypass via webauthn_login |
| CVE-2026-82469 | 5.4 MEDIUM | Rodauth before 2.47.0 Authentication Bypass via jwt_refresh |
| CVE-2026-82470 | 5.4 MEDIUM | Rodauth before 2.47.0 TOTP Code Reuse via Drift Window |
| CVE-2026-82468 | 4.7 MEDIUM | Rodauth before 2.47.0 CSRF Protection Bypass via Content-Type |
No comments yet