{"id":"GHSA-74r7-3mjm-jc5v","aliases":[],"url":"https://o3.security/vulnerability/GHSA-74r7-3mjm-jc5v","summary":"eduMFA: Unauthenticated Failcounter Increment on Resolver Tokens via /validate/check","details":"### Impact\nIf the resolver parameter is passed, but the user does not exist, all failcounters of tokens in that resolver will be increased.\n\n### Patches\nThis, along with other issues, was fixed in eduMFA v2.9.1.\n\n### Workarounds\nLimiting access to `/validate/check` to client applications (i.e. Shibboleth/FreeRADIUS) using an authorization policy with `api_key_required` or using e.g. the reverse proxy.","published":"2026-05-18T15:35:42Z","modified":"2026-05-18T15:48:51.582362Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"edumfa","fixedVersion":"2.9.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/eduMFA/eduMFA/security/advisories/GHSA-74r7-3mjm-jc5v"},{"type":"PACKAGE","url":"https://github.com/eduMFA/eduMFA"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-05-18T15:48:51.582362Z"}}