{"id":"CVE-2022-25838","aliases":["GHSA-6w4v-qr4m-97gg"],"url":"https://o3.security/vulnerability/CVE-2022-25838","summary":"Multi-Factor Authentication issue in Laravel Fortify","details":"Laravel Fortify before 1.11.1 allows reuse within a short time window, thus calling into question the \"OT\" part of the \"TOTP\" concept.","published":"2022-02-24T02:43:16Z","modified":"2026-08-12T03:51:40.025330973Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"laravel/fortify","fixedVersion":"1.11.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/25xxx/CVE-2022-25838.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-25838"},{"type":"REPORT","url":"https://github.com/laravel/fortify/issues/201#issuecomment-1009282153"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:40.025330973Z"}}