Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (2):Search: auth.py

Search Results: "auth.py"

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-10175: Code Injection in Aider-AI AiderCVE-2026-10175
0

A security flaw has been discovered in Aider-AI Aider 0.86.3. Affected by this vulnerability is the function editor_coder.run of the file auth.py of the component Architect Mode. Performing a manipulation results in code injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Join the discussion
CVE-2026-41588: CWE-208: Observable Timing Discrepancy in inducer relateCVE-2026-41588
0

RELATE is a web-based courseware package. Prior to commit 2f68e16, there is a timing attack vulnerability in course/auth.py — check_sign_in_key(). This issue has been patched via commit 2f68e16.

Join the discussion
CVE-2026-41505: CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in inducer relateCVE-2026-41505
0

RELATE is a web-based courseware package. Prior to commit 2f68e16, RELATE is vulnerable to predictable token generation in auth.py's make_sign_in_key() function and exam.py's gen_ticket_code() function. This issue has been patched via commit 2f68e16.

Join the discussion
CVE-2026-7713: Improper Authorization in crocodilestick Calibre-Web-AutomatedCVE-2026-7713
0

A vulnerability was detected in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this vulnerability is the function generate_auth_token of the file cps/kobo_auth.py of the component Kobo auth-token Route. The manipulation results in improper authorization. The attack may be performed from remote. The exploit is now public and may be used. Upgrading to version 4.0.7 addresses this issue. The patch is identified as 9f50bb2c16160564c9f8777dc2ceed3eb95e4807. The affected component should be upgraded.

Join the discussion
CVE-2026-7709: Improper Authorization in janeczku Calibre-WebCVE-2026-7709
0

CVE-2026-7709 is a medium severity vulnerability in janeczku Calibre-Web up to version 0.6.26. It involves improper authorization due to manipulation of the user_id argument in the generate_auth_token function within cps/kobo_auth.py. The vulnerability can be exploited remotely without user interaction. Although an exploit is publicly available, there is no vendor response or official patch as of the publication date.

Join the discussion
CVE-2026-7579: Hard-coded Credentials in AstrBotDevs AstrBotCVE-2026-7579
0

A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.16.0. This issue affects some unknown processing of the file astrbot/dashboard/routes/auth.py of the component Dashboard. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Join the discussion
CVE-2025-15598: Improper Verification of Cryptographic Signature in Dataease SQLBotCVE-2025-15598
0

A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend/apps/system/middleware/auth.py of the component JWT Token Handler. Performing a manipulation results in improper verification of cryptographic signature. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made public and could be used. A comment in the source code warns users about using this feature. The vendor was contacted early about this disclosure.

Join the discussion
CVE-2026-2215: Use of Default Cryptographic Key in rachelos WeRSS we-mp-rssCVE-2026-2215
0

A vulnerability was detected in rachelos WeRSS we-mp-rss up to 1.4.8. This issue affects some unknown processing of the file core/auth.py of the component JWT Handler. Performing a manipulation of the argument SECRET_KEY results in use of default cryptographic key. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is assessed as difficult. The exploit is now public and may be used.

Join the discussion

Showing 1 to 8 of 8 results

Filters:auth.py
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses