rodauth 在 2.47.0 之前的版本中存在一个认证绕过漏洞。该漏洞位于 路由,允许在未提供 refresh token 的情况下签发新的 JWT 访问令牌。攻击者可以通过非 POST 方法向刷新路由提交一个访问令牌,从而获取新的有效访问令牌,从而在仅持有临时访问令牌的情况下实现对账户的无限期访问。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| jeremyevans | rodauth | < 2.47.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| jeremyevans | rodauth | 0 ~ 2.47.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82466 | 8.7 HIGH | Rodauth before 2.46.0 Authentication Bypass via webauthn_login |
| CVE-2026-82470 | 5.4 MEDIUM | Rodauth before 2.47.0 TOTP Code Reuse via Drift Window |
| CVE-2026-82467 | 4.7 MEDIUM | Rodauth before 2.47.0 Open Redirect via Return-to Path |
| CVE-2026-82468 | 4.7 MEDIUM | Rodauth before 2.47.0 CSRF Protection Bypass via Content-Type |
No comments yet