Skip to main content

Vendor archive

scitokens CVEs

Beta · best-effort

5 CVEs tagged to vendor scitokens1 Critical, 4 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2026-32726

Published Mar 31, 2026

SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass in path-based sco…

CVSS 8.1 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-32725

Published Mar 31, 2026

SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass when processing p…

CVSS 8.3 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-32727

Published Mar 31, 2026

SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.7, the Enforcer is vulnerable to a path traversal attack where an attacker can use dot-do…

CVSS 8.1 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-32716

Published Mar 31, 2026

SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the Enforcer incorrectly validates scope paths by using a simple prefix match (startsw…

CVSS 8.1 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-32714

Published Mar 31, 2026

SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the KeyCache class in scitokens was vulnerable to SQL Injection because it used Python…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1