{"id":"PYSEC-2026-1463","summary":"Infrahub: Deleted and expired API tokens can still authenticate","details":"### Impact\nA bug in the authentication logic will cause API tokens that were deleted and/or expired to be considered valid. This means that any API token that is associated with an active user account can authenticate successfully.\n\n### Patches\nThis issue is fixed in versions `1.3.9` and `1.4.5`\n\n### Workarounds\nUsers can delete or deactivate the account associated with a deleted API token to prevent that token from authenticating.","aliases":["CVE-2025-59036","GHSA-v2p7-4pv4-3wwh"],"modified":"2026-07-07T17:47:15.591319861Z","published":"2026-07-07T16:03:04.718927Z","references":[{"type":"WEB","url":"https://github.com/opsmill/infrahub/security/advisories/GHSA-v2p7-4pv4-3wwh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59036"},{"type":"WEB","url":"https://github.com/opsmill/infrahub/commit/215185f217e2f754f7c0a0aa4b77e11079a063a1"},{"type":"WEB","url":"https://github.com/opsmill/infrahub/commit/61b49a4a9e988f10c3a44f0e86ef97f344a1e228"},{"type":"PACKAGE","url":"https://github.com/opsmill/infrahub"},{"type":"WEB","url":"https://github.com/opsmill/infrahub/releases/tag/infrahub-v1.3.9"},{"type":"WEB","url":"https://github.com/opsmill/infrahub/releases/tag/infrahub-v1.4.5"},{"type":"PACKAGE","url":"https://pypi.org/project/infrahub-server"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-v2p7-4pv4-3wwh"}],"affected":[{"package":{"name":"infrahub-server","ecosystem":"PyPI","purl":"pkg:pypi/infrahub-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.9"},{"introduced":"1.4.0"},{"fixed":"1.4.5"}]}],"versions":["1.0.1","1.0.10","1.0.8","1.0.9","1.1.0","1.1.0b2","1.1.1","1.1.10","1.1.2","1.1.3","1.1.4","1.1.5","1.1.6","1.1.7","1.1.8","1.1.9","1.2.0","1.2.0b1","1.2.0rc0","1.2.1","1.2.10","1.2.11","1.2.12","1.2.2","1.2.3","1.2.4","1.2.5","1.2.6","1.2.7","1.2.8","1.2.9","1.2.9rc0","1.3.0","1.3.0a0","1.3.0b1","1.3.0b2","1.3.0b3","1.3.0b5","1.3.0b6","1.3.1","1.3.2","1.3.3","1.3.4","1.3.5","1.3.6","1.3.7","1.3.8","1.4.0","1.4.1","1.4.2","1.4.3","1.4.4"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/infrahub-server/PYSEC-2026-1463.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L"}]}