VulnSea

CWE-294

CVEs classified under CWE-294, newest first.

53 CVEsRSS

CVE-2026-73683High· 8.1
1mo ago

Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attackers to replay captured OIDC id_tokens by exploiting the missing nonce claim validation in the getUserByOIDCToken() fu…

Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attackers to replay captured OIDC id_tokens by exploiting the missing nonce claim validation in the getUserByOIDCToken() fu…

▾ TwilightEPSS 0.76%via NVD
CVE-2026-62911High· 8.0PoC
1mo ago

Microsoft Exchange Server Elevation of Privilege Vulnerability

Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Microsoft Exchange Server 2016 Cumulative Update 23EPSS 0.69%via CVEORG
GHSA-wg23-69c2-gjc8Critical
1mo ago

Craft CMS: Passkey login accepts replayed WebAuthn assertions

Craft CMS: Passkey login accepts replayed WebAuthn assertions

▾ Midnightcraftcms · craftcms/cmsvia GHSA
CVE-2026-16083Medium· 5.3
2mo ago

A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9

A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This affects the function webhook.ParseRequest of the file pkg/channels/line/line.go of the component LINE Webhook. The manipulation results in authentication bypass by …

▾ SunlitEPSS 0.72%via NVD
CVE-2026-57574None
2mo ago

Misskey is an open source, federated social media platform

Misskey is an open source, federated social media platform. Prior to 2026.6.0, Misskey contains a vulnerability in Time-based One-Time Password (TOTP) authentication in UserAuthService where insufficient validation of used tokens allows …

▾ SunlitEPSS 0.55%via NVD
CVE-2026-55370Medium· 6.4
2mo ago

Logto is the modern, open-source auth infrastructure for SaaS and AI apps

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's existing TOTP verification accepted a successfully used TOTP code again while the code remained inside the RFC 6238 acceptance window bec…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-53517High· 8.1
2mo ago

Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption

Better Auth: OAuth refresh-token rotation forks the token family on concurrent redemption

▾ Twilightbetter-auth · @better-auth/oauth-providerEPSS 0.42%via GHSA
CVE-2026-53518High· 8.1
2mo ago

@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive

@better-auth/oauth-provider's OAuth authorization-code grant allows concurrent redemption when two token requests race the find-then-delete primitive

▾ Twilightbetter-auth · @better-auth/oauth-providerEPSS 0.41%via GHSA
CVE-2026-26232None
2mo ago

Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange.

Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange.

▾ SunlitEPSS 0.50%via NVD
CVE-2026-20779High· 7.1
2mo ago

Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be accepted more than once across web two-factor authentication flows and the Basic Auth X-Gitea-OTP path.

Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be accepted more than once across web two-factor authentication flows and the Basic Auth X-Gitea-OTP path.

▾ TwilightEPSS 0.48%via NVD
CVE-2026-8927Critical· 9.1PoC
2mo ago

When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests

When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates agains…

▾ Abyssalhaxx · curlEPSS 0.50%via NVD
CVE-2026-11856Critical· 9.8PoC⚖ disputed
2mo ago

Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongl…

Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongl…

▾ Abyssalhaxx · curlEPSS 0.69%via NVD
CVE-2026-55955Medium· 6.5⚖ disputed
3mo ago

Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55,…

Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55,…

▾ Sunlitapache · tomcatEPSS 0.44%via NVD
GHSA-v2jf-442r-6mjhLow
3mo ago

nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction

nebula-mesh: Signed-poll nonce LRU is in-memory and bounded; replay survives restart + eviction

▾ Sunlitjuev · github.com/juev/nebula-meshvia GHSA
CVE-2023-33854Medium· 5.3
3mo ago

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, and 5.3 could allow an authenticated user to bypass client-side validation and manipulate input data using man in the middle techniques.

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, and 5.3 could allow an authenticated user to bypass client-side validation and manipulate input data using man in the middle techniques.

▾ Sunlitibm · db2EPSS 0.25%via NVD
CVE-2026-54779Medium· 5.9
3mo ago

CoreWCF: SAML token replay protection is inoperative

CoreWCF: SAML token replay protection is inoperative

▾ SunlitCoreWCF · CoreWCF.PrimitivesEPSS 0.43%via GHSA
CVE-2026-54783High· 7.4
3mo ago

CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages

CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages

▾ TwilightCoreWCF · CoreWCF.PrimitivesEPSS 0.19%via GHSA
GHSA-c7jm-38gq-h67hMedium
3mo ago

http4k: `ServerFilters.DigestAuth` / `DigestAuthProvider` defaulted to an always-true nonce verifier, disabling replay protection in default deployments

http4k: `ServerFilters.DigestAuth` / `DigestAuthProvider` defaulted to an always-true nonce verifier, disabling replay protection in default deployments

▾ Sunlithttp4k · org.http4k:http4k-security-digestvia GHSA
CVE-2026-41000Low· 3.7
3mo ago

Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks

Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and creation timestamps, Timestamp element…

▾ Sunlitbroadcom · spring_web_servicesEPSS 0.26%via NVD
CVE-2026-7168Medium· 5.3PoC
4mo ago

Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reusing the same handle, makes libcurl wr…

Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reusing the same handle, makes libcurl wr…

▾ Twilighthaxx · curlEPSS 0.59%via NVD
CVE-2026-30080High· 7.5
5mo ago

OpenAirInterface v2.2.0 accepts Security Mode Complete without any integrity protection

OpenAirInterface v2.2.0 accepts Security Mode Complete without any integrity protection. Configuration has supported integrity NIA1 and NIA2. But if an UE sends initial registration request with only security capability IA0, OpenAirInter…

▾ Twilightopenairinterface · oai-cn5g-amfEPSS 0.35%via NVD
CVE-2026-34209High· 7.5
6mo ago

mppx is a TypeScript interface for machine payments protocol

mppx is a TypeScript interface for machine payments protocol. Prior to version 0.4.11, the tempo/session cooperative close handler validated the close voucher amount using "<" instead of "<=" against the on-chain settled amount. An attac…

▾ Twilightwevm · mppxEPSS 0.44%via NVD
CVE-2020-27374High· 7.5
4y ago

Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to a Replay Attack to BP Monitoring.

Dr Trust USA iCheck Connect BP Monitor BP Testing 118 1.2.1 is vulnerable to a Replay Attack to BP Monitoring.

▾ Twilightdrtrustusa · icheck_connect_bp_monitor_bp_testing_118_firmwareEPSS 0.80%via NVD
CWE-294 vulnerabilities (CVEs) — page 2 · VulnSea