scitokens vulnerabilities
CVEs whose affected-version data names the scitokens package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-32716High· 8.1SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
▾ Twilightscitokens · scitokensEPSS 0.39%via OSV
CVE-2026-32727High· 8.1SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
▾ Twilightscitokens · scitokensEPSS 0.52%via OSV