jeremyevans rodauth
5 known vulnerabilities in jeremyevans rodauth, 1 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-82470 CVSS 5.1 medium Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track the last accepted…
- CVE-2026-82469 CVSS 5.1 medium Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT access tokens without…
- CVE-2026-82468 CVSS 4.9 medium Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation…
- CVE-2026-82467 CVSS 4.9 medium Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested_location, and…
- CVE-2026-82466 CVSS 9.4 critical Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to…