Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/authorizerdev/authorizer
  4. ›
  5. GHSA-jfwg-rxf3-p7r9

GHSA-jfwg-rxf3-p7r9: Authorizer: CQL/N1QL Injection in Cassandra and Couchbase Backends via fmt.Sprintf String Interpolation

April 6, 2026

An unauthenticated attacker can inject arbitrary CQL operators through the email, phone, or token parameters on public-facing endpoints (signup, login, forgot_password, magic_link_login). This enables authentication bypass and data exfiltration from the Cassandra keyspace.

References

  • github.com/advisories/GHSA-jfwg-rxf3-p7r9
  • github.com/authorizerdev/authorizer
  • github.com/authorizerdev/authorizer/commit/73679faa53cd215c7524d651046e402c43809786
  • github.com/authorizerdev/authorizer/pull/500
  • github.com/authorizerdev/authorizer/releases/tag/2.0.1
  • github.com/authorizerdev/authorizer/security/advisories/GHSA-jfwg-rxf3-p7r9

Code Behaviors & Features

Detect and mitigate GHSA-jfwg-rxf3-p7r9 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 0.0.0-20260327055742-73679faa53cd

Fixed versions

  • 0.0.0-20260327055742-73679faa53cd

Solution

Upgrade to version 0.0.0-20260327055742-73679faa53cd or above.

Impact 7.3 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Learn more about CVSS

Weakness

  • CWE-209: Generation of Error Message Containing Sensitive Information
  • CWE-943: Improper Neutralization of Special Elements in Data Query Logic

Source file

go/github.com/authorizerdev/authorizer/GHSA-jfwg-rxf3-p7r9.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 09 May 2026 12:18:08 +0000.