Threats Tagged 'ghsa-w4vj-gm7w-293h'
View all threats tagged with 'ghsa-w4vj-gm7w-293h'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-w4vj-gm7w-293h'
Click on any threat for detailed analysis and mitigation recommendations
Vulnerability-Lookup contains an authentication weakness in its account activation and password-recovery mechanism. (CVE-2026-73431)CVE-2026-73431 0 Vulnerability-Lookup has an authentication weakness in its account activation and password-recovery mechanism. Stateless signed tokens containing only the user's login were used for activation and recovery links. These tokens remained valid for the entire configured validity period even after password changes, allowing replay attacks. Tokens were also not bound to specific purposes, enabling reuse across workflows. The vulnerability allows an attacker who obtains a valid token to repeatedly reset the password and take control of the account without needing the victim's password or an authenticated session. Join the discussion | GCVE Database | 08/12/2026, 15:30:50 UTC Added: 08/12/2026, 16:11:06 UTC |
Showing 1 to 1 of 1 result