jeremyevans rodauth

5 known vulnerabilities in jeremyevans rodauth, 1 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-82470 CVSS 5.1 medium Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track the last accepted…
  • CVE-2026-82469 CVSS 5.1 medium Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT access tokens without…
  • CVE-2026-82468 CVSS 4.9 medium Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation…
  • CVE-2026-82467 CVSS 4.9 medium Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested_location, and…
  • CVE-2026-82466 CVSS 9.4 critical Rodauth before 2.46.0 contains an authentication bypass vulnerability in the webauthn_login route that allows logged-in users to…