{"id":"GHSA-j5rm-v3vh-vx94","summary":"eduMFA Passkeys: missing expiration flag may allow replay attacks and reuse of old challenges ","details":"### Impact\nIn eduMFA \u003c 2.9.1 userless Passkey/WebAuthn challenges might be replayed and do not expire\n\n### Patches\nFixed in eduMFA \u003e= 2.9.1 by adding validity information to the userless challenges.\n\n### Workarounds\nNo known workarounds besides disabling userless login altogether.","modified":"2026-05-18T15:48:04.309551Z","published":"2026-05-18T15:37:00Z","database_specific":{"cwe_ids":["CWE-287","CWE-613"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-05-18T15:37:00Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/eduMFA/eduMFA/security/advisories/GHSA-j5rm-v3vh-vx94"},{"type":"PACKAGE","url":"https://github.com/eduMFA/eduMFA"}],"affected":[{"package":{"name":"edumfa","ecosystem":"PyPI","purl":"pkg:pypi/edumfa"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.9.1"}]}],"versions":["1.2.0","1.3.0","1.4.0","1.5.0","1.5.1","2.0.0","2.0.1","2.0.2","2.0.3","2.1.0","2.2.0","2.3.0","2.4.0","2.5.0","2.6.0","2.6.1","2.7.0","2.7.1","2.7.2","2.8.0","2.9.0","2.9.0rc1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-j5rm-v3vh-vx94/GHSA-j5rm-v3vh-vx94.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}