{"id":"GHSA-74r7-3mjm-jc5v","summary":"eduMFA: Unauthenticated Failcounter Increment on Resolver Tokens via /validate/check","details":"### Impact\nIf the resolver parameter is passed, but the user does not exist, all failcounters of tokens in that resolver will be increased.\n\n### Patches\nThis, along with other issues, was fixed in eduMFA v2.9.1.\n\n### Workarounds\nLimiting access to `/validate/check` to client applications (i.e. Shibboleth/FreeRADIUS) using an authorization policy with `api_key_required` or using e.g. the reverse proxy.","modified":"2026-05-18T15:48:51.582362Z","published":"2026-05-18T15:35:42Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-05-18T15:35:42Z","nvd_published_at":null,"cwe_ids":["CWE-20"]},"references":[{"type":"WEB","url":"https://github.com/eduMFA/eduMFA/security/advisories/GHSA-74r7-3mjm-jc5v"},{"type":"PACKAGE","url":"https://github.com/eduMFA/eduMFA"}],"affected":[{"package":{"name":"edumfa","ecosystem":"PyPI","purl":"pkg:pypi/edumfa"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.9.1"}]}],"versions":["1.2.0","1.3.0","1.4.0","1.5.0","1.5.1","2.0.0","2.0.1","2.0.2","2.0.3","2.1.0","2.2.0","2.3.0","2.4.0","2.5.0","2.6.0","2.6.1","2.7.0","2.7.1","2.7.2","2.8.0","2.9.0","2.9.0rc1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-74r7-3mjm-jc5v/GHSA-74r7-3mjm-jc5v.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}