Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

ubuntu логотип

CVE-2026-34531

5 месяцев назад

Flask-HTTPAuth provides Basic, Digest and Token HTTP authentication for Flask routes. Prior to version 4.8.1, in a situation where the client makes a request to a token protected resource without passing a token, or passing an empty token, Flask-HTTPAuth would invoke the application's token verification callback function with the token argument set to an empty string. If the application had any users in its database with an empty string set as their token, then it could potentially authenticate the client request against any of those users. This issue has been patched in version 4.8.1.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-34531

5 месяцев назад

Flask-HTTPAuth provides Basic, Digest and Token HTTP authentication for Flask routes. Prior to version 4.8.1, in a situation where the client makes a request to a token protected resource without passing a token, or passing an empty token, Flask-HTTPAuth would invoke the application's token verification callback function with the token argument set to an empty string. If the application had any users in its database with an empty string set as their token, then it could potentially authenticate the client request against any of those users. This issue has been patched in version 4.8.1.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2026-34531

5 месяцев назад

Flask-HTTPAuth provides Basic, Digest and Token HTTP authentication fo ...

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20576-1

4 месяца назад

Security update for python-Flask-HTTPAuth

EPSS: Низкий
github логотип

GHSA-p44q-vqpr-4xmg

5 месяцев назад

Flask-HTTPAuth invokes token verification callback when missing or empty token was given by client

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-34531

Flask-HTTPAuth provides Basic, Digest and Token HTTP authentication for Flask routes. Prior to version 4.8.1, in a situation where the client makes a request to a token protected resource without passing a token, or passing an empty token, Flask-HTTPAuth would invoke the application's token verification callback function with the token argument set to an empty string. If the application had any users in its database with an empty string set as their token, then it could potentially authenticate the client request against any of those users. This issue has been patched in version 4.8.1.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-34531

Flask-HTTPAuth provides Basic, Digest and Token HTTP authentication for Flask routes. Prior to version 4.8.1, in a situation where the client makes a request to a token protected resource without passing a token, or passing an empty token, Flask-HTTPAuth would invoke the application's token verification callback function with the token argument set to an empty string. If the application had any users in its database with an empty string set as their token, then it could potentially authenticate the client request against any of those users. This issue has been patched in version 4.8.1.

CVSS3: 6.5
0%
Низкий
5 месяцев назад
debian логотип
CVE-2026-34531

Flask-HTTPAuth provides Basic, Digest and Token HTTP authentication fo ...

CVSS3: 6.5
0%
Низкий
5 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20576-1

Security update for python-Flask-HTTPAuth

0%
Низкий
4 месяца назад
github логотип
GHSA-p44q-vqpr-4xmg

Flask-HTTPAuth invokes token verification callback when missing or empty token was given by client

CVSS3: 6.5
0%
Низкий
5 месяцев назад

Уязвимостей на страницу