All 5 CVE vulnerabilities found in rodauth, with AI-generated Chinese analysis, references, and POCs.
Vendor: jeremyevans
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-82470 | Rodauth before 2.47.0 TOTP Code Reuse via Drift Window CWE-294 | 5.4 | Medium | 2026-08-29 |
| CVE-2026-82469 | Rodauth before 2.47.0 Authentication Bypass via jwt_refresh CWE-613 | 5.4 | Medium | 2026-08-29 |
| CVE-2026-82467 | Rodauth before 2.47.0 Open Redirect via Return-to Path CWE-601 | 4.7 | Medium | 2026-08-29 |
| CVE-2026-82468 | Rodauth before 2.47.0 CSRF Protection Bypass via Content-Type CWE-352 | 4.7 | Medium | 2026-08-29 |
| CVE-2026-82466 | Rodauth before 2.46.0 Authentication Bypass via webauthn_login CWE-287 | 8.7 | High | 2026-08-29 |
All 5 known CVE vulnerabilities affecting rodauth with full Chinese analysis, references, and POCs where available.