Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. edumfa
  4. ›
  5. GHSA-qq2p-4282-cfc5

GHSA-qq2p-4282-cfc5: eduMFA: Incorrect InnoDB snapshot isolation possibly allows token reusage

May 18, 2026

For deployments using MySQL or MariaDB < 11.6.2 (or newer with innodb_snapshot_isolation=off) reusage of token values might be possible due to faulty transaction isolation inside the database. Exploiting this requires racing this transaction. Affected are all tokentypes whose values are only supposed to be used once, for example TOTP, HOTP and likely also WebAuthN.

References

  • github.com/advisories/GHSA-qq2p-4282-cfc5
  • github.com/eduMFA/eduMFA/security/advisories/GHSA-qq2p-4282-cfc5

Code Behaviors & Features

Detect and mitigate GHSA-qq2p-4282-cfc5 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.9.1

Fixed versions

  • 2.9.1

Solution

Upgrade to version 2.9.1 or above.

Impact 7.1 HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:L

Learn more about CVSS

Weakness

  • CWE-285: Improper Authorization

Source file

pypi/edumfa/GHSA-qq2p-4282-cfc5.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 23 Jun 2026 12:24:43 +0000.