highVulnerability
GHSA-j5rm-v3vh-vx94
### Impact In eduMFA < 2.9.1 userless Passkey/WebAuthn challenges might be replayed and do not expire ### Patches Fixed in eduMFA >= 2.9.1 by adding validity information to the userless challenges. ### Workarounds No known workarounds besides disabling userless login altogether.
Properties
- ghsa_id
- GHSA-j5rm-v3vh-vx94
- severity
- high
- summary
- eduMFA Passkeys: missing expiration flag may allow replay attacks and reuse of old challenges
- cve_id
- GHSA-j5rm-v3vh-vx94
- is_ghsa_only
- true
- ghsa_published
- 2026-05-18T15:37:00Z
- source_url
- https://github.com/advisories/GHSA-j5rm-v3vh-vx94
- ghsa_updated
- 2026-05-18T15:37:01Z
Related Entities (5)
VULNERABLE_TO (1)
←[Software]pip/edumfa
AFFECTS (1)
→[Software]pip/edumfa
HAS_WEAKNESS (2)
→[Weakness]Improper Authentication
→[Weakness]Insufficient Session Expiration
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph