CVE-2026-34531: CWE-287: Improper Authentication in miguelgrinberg Flask-HTTPAuth
Flask-HTTPAuth provides Basic, Digest and Token HTTP authentication for Flask routes. Prior to version 4.8.1, in a situation where the client makes a request to a token protected resource without passing a token, or passing an empty token, Flask-HTTPAuth would invoke the application's token verification callback function with the token argument set to an empty string. If the application had any users in its database with an empty string set as their token, then it could potentially authenticate the client request against any of those users. This issue has been patched in version 4.8.1.
AI Analysis
Technical Summary
Flask-HTTPAuth is a Flask extension providing HTTP authentication mechanisms including token authentication. Before version 4.8.1, when a client request to a token-protected endpoint omitted the token or provided an empty token, the framework would call the token verification callback with an empty string token. Applications that store users with an empty string as their token could inadvertently authenticate such requests as those users, leading to improper authentication (CWE-287). This vulnerability has been addressed in Flask-HTTPAuth version 4.8.1.
Potential Impact
An attacker could potentially gain unauthorized access to resources protected by token authentication if the application has users with empty string tokens. This could lead to unauthorized actions under those user identities. The CVSS score is 6.5 (medium severity), indicating a moderate impact with low confidentiality impact but high integrity impact. There are no known exploits in the wild.
Mitigation Recommendations
Upgrade Flask-HTTPAuth to version 4.8.1 or later, where this issue is patched. Applications should also ensure that no users have empty string tokens assigned. Patch status is confirmed fixed in version 4.8.1.
CVE-2026-34531: CWE-287: Improper Authentication in miguelgrinberg Flask-HTTPAuth
Description
Flask-HTTPAuth provides Basic, Digest and Token HTTP authentication for Flask routes. Prior to version 4.8.1, in a situation where the client makes a request to a token protected resource without passing a token, or passing an empty token, Flask-HTTPAuth would invoke the application's token verification callback function with the token argument set to an empty string. If the application had any users in its database with an empty string set as their token, then it could potentially authenticate the client request against any of those users. This issue has been patched in version 4.8.1.
CVSS v3.1
Score 6.5medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Flask-HTTPAuth is a Flask extension providing HTTP authentication mechanisms including token authentication. Before version 4.8.1, when a client request to a token-protected endpoint omitted the token or provided an empty token, the framework would call the token verification callback with an empty string token. Applications that store users with an empty string as their token could inadvertently authenticate such requests as those users, leading to improper authentication (CWE-287). This vulnerability has been addressed in Flask-HTTPAuth version 4.8.1.
Potential Impact
An attacker could potentially gain unauthorized access to resources protected by token authentication if the application has users with empty string tokens. This could lead to unauthorized actions under those user identities. The CVSS score is 6.5 (medium severity), indicating a moderate impact with low confidentiality impact but high integrity impact. There are no known exploits in the wild.
Mitigation Recommendations
Upgrade Flask-HTTPAuth to version 4.8.1 or later, where this issue is patched. Applications should also ensure that no users have empty string tokens assigned. Patch status is confirmed fixed in version 4.8.1.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-03-30T16:03:31.048Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 69cd8944e6bfc5ba1dfc32e5
Added to database: 04/01/2026, 21:08:20 UTC
Last enriched: 05/28/2026, 19:56:20 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 145
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.