rdiffweb
A web interface to rdiff-backup repositories.
Activity
- Latest release
- 2w ago
- Total releases
- 173
- Cadence
- ~12 days
- Last 12 months
- 29
Details
- License
- custom
- First release
- Oct 07, 2016
| Version | Released | |
|---|---|---|
7.1.1
patch
|
7.1.1
patch
Dependencies (20)
+ 12 more |
|
7.1.0
minor
|
7.1.0
minor
Dependencies (20)
+ 12 more |
|
7.1.0b3
pre
|
7.1.0b3
pre
Dependencies (20)
+ 12 more |
|
7.1.0b2
pre
|
7.1.0b2
pre
Dependencies (20)
+ 12 more |
|
7.1.0b1
pre
|
7.1.0b1
pre
Dependencies (20)
+ 12 more |
|
7.0.1
patch
|
7.0.1
patch
Dependencies (20)
+ 12 more |
|
7.0.0
major
|
7.0.0
major
Dependencies (20)
+ 12 more |
|
7.0.0b8
pre
|
7.0.0b8
pre
Dependencies (20)
+ 12 more |
|
7.0.0b7
pre
|
7.0.0b7
pre
Dependencies (20)
+ 12 more |
|
7.0.0b6
pre
|
7.0.0b6
pre
Dependencies (20)
+ 12 more |
|
7.0.0b5
pre
|
7.0.0b5
pre
Dependencies (20)
+ 12 more |
|
7.0.0b4
pre
|
7.0.0b4
pre
Dependencies (20)
+ 12 more |
|
7.0.0b3
pre
|
7.0.0b3
pre
Dependencies (20)
+ 12 more |
|
7.0.0b2
pre
|
7.0.0b2
pre
Dependencies (20)
+ 12 more |
|
7.0.0b1
pre
|
7.0.0b1
pre
Dependencies (20)
+ 12 more |
|
7.0.0a1
pre
|
7.0.0a1
pre
Dependencies (19)
+ 11 more |
|
2.12.0b1
pre
|
2.12.0b1
pre
Dependencies (18)
+ 10 more |
|
2.11.5
patch
|
2.11.5
patch
Dependencies (25)
+ 17 more |
|
2.11.4
patch
|
2.11.4
patch
Dependencies (25)
+ 17 more |
|
2.11.3
patch
|
2.11.3
patch
Dependencies (25)
+ 17 more |
|
2.11.2
patch
|
2.11.2
patch
Dependencies (25)
+ 17 more |
|
2.11.1
patch
|
2.11.1
patch
Dependencies (25)
+ 17 more |
|
2.11.0
minor
|
2.11.0
minor
Dependencies (25)
+ 17 more |
|
2.11.0b5
pre
|
2.11.0b5
pre
Dependencies (25)
+ 17 more |
|
2.11.0b4
pre
|
2.11.0b4
pre
Dependencies (25)
+ 17 more |
|
2.11.0b3
pre
|
2.11.0b3
pre
Dependencies (25)
+ 17 more |
|
2.11.0b2
pre
|
2.11.0b2
pre
Dependencies (25)
+ 17 more |
|
2.11.0b1
pre
|
2.11.0b1
pre
Dependencies (25)
+ 17 more |
|
2.10.6
patch
|
2.10.6
patch
Dependencies (24)
+ 16 more |
|
2.10.5
patch
1 CVE
CVE-2025-67796
PYSEC-2026-3048
GHSA-v4gp-hf5j-4566
Jul 13, 2026
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
IKUS Rdiffweb version 2.10.5 and below have an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6. Affected versions
0.10.0
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.9.2.dev1
0.9.3
0.9.4
+ 132 more Show less
0.9.5
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.1b1
1.3.1b2
1.3.2
1.4.0
1.4.0b1
1.4.0b2
1.4.0b3
1.4.0b4
1.4.0b5
1.4.1b1
1.4.1b2
1.4.1b3
1.5.0
1.5.1b1
1.5.1b2
1.6.0b1
2.0.1b2
2.0.1b3
2.0.2
2.0.3a1
2.0.3a2
2.0.3a3
2.0.3a4
2.0.3a5
2.0.3a6
2.0.3a7
2.1.0
2.10.3b1
2.10.4
2.10.4b1
2.10.4b2
2.10.5
2.2.0
2.2.0.dev1
2.2.0a1
2.2.0a2
2.2.0a3
2.2.0a4
2.2.0a5
2.2.0a6
2.2.1
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.11a1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.0a7
2.5.0a8
2.5.0a9
2.5.1
2.5.2
2.5.3
2.5.4
2.5.4b1
2.5.5
2.5.6
2.5.7
2.5.8
2.6.0
2.6.0a1
2.6.0a2
2.6.0a3
2.6.0a4
2.6.1
2.7.0
2.7.0a1
2.7.0a2
2.7.0a3
2.7.1
2.8.0a1
2.8.0a2
2.8.0a3
2.8.0a4
2.8.0a5
2.8.0a6
2.8.0a7
2.8.0a8
2.8.0a9
2.8.1
2.8.2
2.8.2a1
2.8.3
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
2.9.0a3
2.9.0a5
2.9.0b1
2.9.0b2
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5
2.9.7
Fixed in
2.10.6
References Updated Jul 13, 2026 · Source: OSV.dev |
2.10.5
patch
Dependencies (23)
+ 15 more |
|
2.10.4
minor
1 CVE
CVE-2025-67796
PYSEC-2026-3048
GHSA-v4gp-hf5j-4566
Jul 13, 2026
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
IKUS Rdiffweb version 2.10.5 and below have an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6. Affected versions
0.10.0
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.9.2.dev1
0.9.3
0.9.4
+ 132 more Show less
0.9.5
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.1b1
1.3.1b2
1.3.2
1.4.0
1.4.0b1
1.4.0b2
1.4.0b3
1.4.0b4
1.4.0b5
1.4.1b1
1.4.1b2
1.4.1b3
1.5.0
1.5.1b1
1.5.1b2
1.6.0b1
2.0.1b2
2.0.1b3
2.0.2
2.0.3a1
2.0.3a2
2.0.3a3
2.0.3a4
2.0.3a5
2.0.3a6
2.0.3a7
2.1.0
2.10.3b1
2.10.4
2.10.4b1
2.10.4b2
2.10.5
2.2.0
2.2.0.dev1
2.2.0a1
2.2.0a2
2.2.0a3
2.2.0a4
2.2.0a5
2.2.0a6
2.2.1
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.11a1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.0a7
2.5.0a8
2.5.0a9
2.5.1
2.5.2
2.5.3
2.5.4
2.5.4b1
2.5.5
2.5.6
2.5.7
2.5.8
2.6.0
2.6.0a1
2.6.0a2
2.6.0a3
2.6.0a4
2.6.1
2.7.0
2.7.0a1
2.7.0a2
2.7.0a3
2.7.1
2.8.0a1
2.8.0a2
2.8.0a3
2.8.0a4
2.8.0a5
2.8.0a6
2.8.0a7
2.8.0a8
2.8.0a9
2.8.1
2.8.2
2.8.2a1
2.8.3
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
2.9.0a3
2.9.0a5
2.9.0b1
2.9.0b2
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5
2.9.7
Fixed in
2.10.6
References Updated Jul 13, 2026 · Source: OSV.dev |
2.10.4
minor
Dependencies (23)
+ 15 more |
|
2.10.4b2
pre
1 CVE
CVE-2025-67796
PYSEC-2026-3048
GHSA-v4gp-hf5j-4566
Jul 13, 2026
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
IKUS Rdiffweb version 2.10.5 and below have an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6. Affected versions
0.10.0
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.9.2.dev1
0.9.3
0.9.4
+ 132 more Show less
0.9.5
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.1b1
1.3.1b2
1.3.2
1.4.0
1.4.0b1
1.4.0b2
1.4.0b3
1.4.0b4
1.4.0b5
1.4.1b1
1.4.1b2
1.4.1b3
1.5.0
1.5.1b1
1.5.1b2
1.6.0b1
2.0.1b2
2.0.1b3
2.0.2
2.0.3a1
2.0.3a2
2.0.3a3
2.0.3a4
2.0.3a5
2.0.3a6
2.0.3a7
2.1.0
2.10.3b1
2.10.4
2.10.4b1
2.10.4b2
2.10.5
2.2.0
2.2.0.dev1
2.2.0a1
2.2.0a2
2.2.0a3
2.2.0a4
2.2.0a5
2.2.0a6
2.2.1
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.11a1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.0a7
2.5.0a8
2.5.0a9
2.5.1
2.5.2
2.5.3
2.5.4
2.5.4b1
2.5.5
2.5.6
2.5.7
2.5.8
2.6.0
2.6.0a1
2.6.0a2
2.6.0a3
2.6.0a4
2.6.1
2.7.0
2.7.0a1
2.7.0a2
2.7.0a3
2.7.1
2.8.0a1
2.8.0a2
2.8.0a3
2.8.0a4
2.8.0a5
2.8.0a6
2.8.0a7
2.8.0a8
2.8.0a9
2.8.1
2.8.2
2.8.2a1
2.8.3
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
2.9.0a3
2.9.0a5
2.9.0b1
2.9.0b2
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5
2.9.7
Fixed in
2.10.6
References Updated Jul 13, 2026 · Source: OSV.dev |
2.10.4b2
pre
Dependencies (23)
+ 15 more |
|
2.10.4b1
pre
1 CVE
CVE-2025-67796
PYSEC-2026-3048
GHSA-v4gp-hf5j-4566
Jul 13, 2026
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
IKUS Rdiffweb version 2.10.5 and below have an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6. Affected versions
0.10.0
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.9.2.dev1
0.9.3
0.9.4
+ 132 more Show less
0.9.5
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.1b1
1.3.1b2
1.3.2
1.4.0
1.4.0b1
1.4.0b2
1.4.0b3
1.4.0b4
1.4.0b5
1.4.1b1
1.4.1b2
1.4.1b3
1.5.0
1.5.1b1
1.5.1b2
1.6.0b1
2.0.1b2
2.0.1b3
2.0.2
2.0.3a1
2.0.3a2
2.0.3a3
2.0.3a4
2.0.3a5
2.0.3a6
2.0.3a7
2.1.0
2.10.3b1
2.10.4
2.10.4b1
2.10.4b2
2.10.5
2.2.0
2.2.0.dev1
2.2.0a1
2.2.0a2
2.2.0a3
2.2.0a4
2.2.0a5
2.2.0a6
2.2.1
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.11a1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.0a7
2.5.0a8
2.5.0a9
2.5.1
2.5.2
2.5.3
2.5.4
2.5.4b1
2.5.5
2.5.6
2.5.7
2.5.8
2.6.0
2.6.0a1
2.6.0a2
2.6.0a3
2.6.0a4
2.6.1
2.7.0
2.7.0a1
2.7.0a2
2.7.0a3
2.7.1
2.8.0a1
2.8.0a2
2.8.0a3
2.8.0a4
2.8.0a5
2.8.0a6
2.8.0a7
2.8.0a8
2.8.0a9
2.8.1
2.8.2
2.8.2a1
2.8.3
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
2.9.0a3
2.9.0a5
2.9.0b1
2.9.0b2
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5
2.9.7
Fixed in
2.10.6
References Updated Jul 13, 2026 · Source: OSV.dev |
2.10.4b1
pre
Dependencies (23)
+ 15 more |
|
2.10.3b1
pre
1 CVE
CVE-2025-67796
PYSEC-2026-3048
GHSA-v4gp-hf5j-4566
Jul 13, 2026
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
IKUS Rdiffweb version 2.10.5 and below have an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6. Affected versions
0.10.0
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.9.2.dev1
0.9.3
0.9.4
+ 132 more Show less
0.9.5
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.1b1
1.3.1b2
1.3.2
1.4.0
1.4.0b1
1.4.0b2
1.4.0b3
1.4.0b4
1.4.0b5
1.4.1b1
1.4.1b2
1.4.1b3
1.5.0
1.5.1b1
1.5.1b2
1.6.0b1
2.0.1b2
2.0.1b3
2.0.2
2.0.3a1
2.0.3a2
2.0.3a3
2.0.3a4
2.0.3a5
2.0.3a6
2.0.3a7
2.1.0
2.10.3b1
2.10.4
2.10.4b1
2.10.4b2
2.10.5
2.2.0
2.2.0.dev1
2.2.0a1
2.2.0a2
2.2.0a3
2.2.0a4
2.2.0a5
2.2.0a6
2.2.1
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.11a1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.0a7
2.5.0a8
2.5.0a9
2.5.1
2.5.2
2.5.3
2.5.4
2.5.4b1
2.5.5
2.5.6
2.5.7
2.5.8
2.6.0
2.6.0a1
2.6.0a2
2.6.0a3
2.6.0a4
2.6.1
2.7.0
2.7.0a1
2.7.0a2
2.7.0a3
2.7.1
2.8.0a1
2.8.0a2
2.8.0a3
2.8.0a4
2.8.0a5
2.8.0a6
2.8.0a7
2.8.0a8
2.8.0a9
2.8.1
2.8.2
2.8.2a1
2.8.3
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
2.9.0a3
2.9.0a5
2.9.0b1
2.9.0b2
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5
2.9.7
Fixed in
2.10.6
References Updated Jul 13, 2026 · Source: OSV.dev |
2.10.3b1
pre
Dependencies (23)
+ 15 more |
|
2.9.7
patch
1 CVE
CVE-2025-67796
PYSEC-2026-3048
GHSA-v4gp-hf5j-4566
Jul 13, 2026
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
IKUS Rdiffweb version 2.10.5 and below have an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6. Affected versions
0.10.0
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.9.2.dev1
0.9.3
0.9.4
+ 132 more Show less
0.9.5
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.1b1
1.3.1b2
1.3.2
1.4.0
1.4.0b1
1.4.0b2
1.4.0b3
1.4.0b4
1.4.0b5
1.4.1b1
1.4.1b2
1.4.1b3
1.5.0
1.5.1b1
1.5.1b2
1.6.0b1
2.0.1b2
2.0.1b3
2.0.2
2.0.3a1
2.0.3a2
2.0.3a3
2.0.3a4
2.0.3a5
2.0.3a6
2.0.3a7
2.1.0
2.10.3b1
2.10.4
2.10.4b1
2.10.4b2
2.10.5
2.2.0
2.2.0.dev1
2.2.0a1
2.2.0a2
2.2.0a3
2.2.0a4
2.2.0a5
2.2.0a6
2.2.1
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.11a1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.0a7
2.5.0a8
2.5.0a9
2.5.1
2.5.2
2.5.3
2.5.4
2.5.4b1
2.5.5
2.5.6
2.5.7
2.5.8
2.6.0
2.6.0a1
2.6.0a2
2.6.0a3
2.6.0a4
2.6.1
2.7.0
2.7.0a1
2.7.0a2
2.7.0a3
2.7.1
2.8.0a1
2.8.0a2
2.8.0a3
2.8.0a4
2.8.0a5
2.8.0a6
2.8.0a7
2.8.0a8
2.8.0a9
2.8.1
2.8.2
2.8.2a1
2.8.3
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
2.9.0a3
2.9.0a5
2.9.0b1
2.9.0b2
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5
2.9.7
Fixed in
2.10.6
References Updated Jul 13, 2026 · Source: OSV.dev |
2.9.7
patch
Dependencies (23)
+ 15 more |
|
2.9.5
patch
1 CVE
CVE-2025-67796
PYSEC-2026-3048
GHSA-v4gp-hf5j-4566
Jul 13, 2026
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
IKUS Rdiffweb version 2.10.5 and below have an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6. Affected versions
0.10.0
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.9.2.dev1
0.9.3
0.9.4
+ 132 more Show less
0.9.5
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.1b1
1.3.1b2
1.3.2
1.4.0
1.4.0b1
1.4.0b2
1.4.0b3
1.4.0b4
1.4.0b5
1.4.1b1
1.4.1b2
1.4.1b3
1.5.0
1.5.1b1
1.5.1b2
1.6.0b1
2.0.1b2
2.0.1b3
2.0.2
2.0.3a1
2.0.3a2
2.0.3a3
2.0.3a4
2.0.3a5
2.0.3a6
2.0.3a7
2.1.0
2.10.3b1
2.10.4
2.10.4b1
2.10.4b2
2.10.5
2.2.0
2.2.0.dev1
2.2.0a1
2.2.0a2
2.2.0a3
2.2.0a4
2.2.0a5
2.2.0a6
2.2.1
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.11a1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.0a7
2.5.0a8
2.5.0a9
2.5.1
2.5.2
2.5.3
2.5.4
2.5.4b1
2.5.5
2.5.6
2.5.7
2.5.8
2.6.0
2.6.0a1
2.6.0a2
2.6.0a3
2.6.0a4
2.6.1
2.7.0
2.7.0a1
2.7.0a2
2.7.0a3
2.7.1
2.8.0a1
2.8.0a2
2.8.0a3
2.8.0a4
2.8.0a5
2.8.0a6
2.8.0a7
2.8.0a8
2.8.0a9
2.8.1
2.8.2
2.8.2a1
2.8.3
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
2.9.0a3
2.9.0a5
2.9.0b1
2.9.0b2
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5
2.9.7
Fixed in
2.10.6
References Updated Jul 13, 2026 · Source: OSV.dev |
2.9.5
patch
Dependencies (22)
+ 14 more |
|
2.9.4
patch
1 CVE
CVE-2025-67796
PYSEC-2026-3048
GHSA-v4gp-hf5j-4566
Jul 13, 2026
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
IKUS Rdiffweb version 2.10.5 and below have an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6. Affected versions
0.10.0
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.9.2.dev1
0.9.3
0.9.4
+ 132 more Show less
0.9.5
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.1b1
1.3.1b2
1.3.2
1.4.0
1.4.0b1
1.4.0b2
1.4.0b3
1.4.0b4
1.4.0b5
1.4.1b1
1.4.1b2
1.4.1b3
1.5.0
1.5.1b1
1.5.1b2
1.6.0b1
2.0.1b2
2.0.1b3
2.0.2
2.0.3a1
2.0.3a2
2.0.3a3
2.0.3a4
2.0.3a5
2.0.3a6
2.0.3a7
2.1.0
2.10.3b1
2.10.4
2.10.4b1
2.10.4b2
2.10.5
2.2.0
2.2.0.dev1
2.2.0a1
2.2.0a2
2.2.0a3
2.2.0a4
2.2.0a5
2.2.0a6
2.2.1
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.11a1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.0a7
2.5.0a8
2.5.0a9
2.5.1
2.5.2
2.5.3
2.5.4
2.5.4b1
2.5.5
2.5.6
2.5.7
2.5.8
2.6.0
2.6.0a1
2.6.0a2
2.6.0a3
2.6.0a4
2.6.1
2.7.0
2.7.0a1
2.7.0a2
2.7.0a3
2.7.1
2.8.0a1
2.8.0a2
2.8.0a3
2.8.0a4
2.8.0a5
2.8.0a6
2.8.0a7
2.8.0a8
2.8.0a9
2.8.1
2.8.2
2.8.2a1
2.8.3
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
2.9.0a3
2.9.0a5
2.9.0b1
2.9.0b2
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5
2.9.7
Fixed in
2.10.6
References Updated Jul 13, 2026 · Source: OSV.dev |
2.9.4
patch
Dependencies (22)
+ 14 more |
|
2.9.3
patch
1 CVE
CVE-2025-67796
PYSEC-2026-3048
GHSA-v4gp-hf5j-4566
Jul 13, 2026
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
IKUS Rdiffweb version 2.10.5 and below have an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6. Affected versions
0.10.0
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.9.2.dev1
0.9.3
0.9.4
+ 132 more Show less
0.9.5
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.1b1
1.3.1b2
1.3.2
1.4.0
1.4.0b1
1.4.0b2
1.4.0b3
1.4.0b4
1.4.0b5
1.4.1b1
1.4.1b2
1.4.1b3
1.5.0
1.5.1b1
1.5.1b2
1.6.0b1
2.0.1b2
2.0.1b3
2.0.2
2.0.3a1
2.0.3a2
2.0.3a3
2.0.3a4
2.0.3a5
2.0.3a6
2.0.3a7
2.1.0
2.10.3b1
2.10.4
2.10.4b1
2.10.4b2
2.10.5
2.2.0
2.2.0.dev1
2.2.0a1
2.2.0a2
2.2.0a3
2.2.0a4
2.2.0a5
2.2.0a6
2.2.1
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.11a1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.0a7
2.5.0a8
2.5.0a9
2.5.1
2.5.2
2.5.3
2.5.4
2.5.4b1
2.5.5
2.5.6
2.5.7
2.5.8
2.6.0
2.6.0a1
2.6.0a2
2.6.0a3
2.6.0a4
2.6.1
2.7.0
2.7.0a1
2.7.0a2
2.7.0a3
2.7.1
2.8.0a1
2.8.0a2
2.8.0a3
2.8.0a4
2.8.0a5
2.8.0a6
2.8.0a7
2.8.0a8
2.8.0a9
2.8.1
2.8.2
2.8.2a1
2.8.3
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
2.9.0a3
2.9.0a5
2.9.0b1
2.9.0b2
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5
2.9.7
Fixed in
2.10.6
References Updated Jul 13, 2026 · Source: OSV.dev |
2.9.3
patch
Dependencies (22)
+ 14 more |
|
2.9.2
patch
1 CVE
CVE-2025-67796
PYSEC-2026-3048
GHSA-v4gp-hf5j-4566
Jul 13, 2026
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
IKUS Rdiffweb version 2.10.5 and below have an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6. Affected versions
0.10.0
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.9.2.dev1
0.9.3
0.9.4
+ 132 more Show less
0.9.5
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.1b1
1.3.1b2
1.3.2
1.4.0
1.4.0b1
1.4.0b2
1.4.0b3
1.4.0b4
1.4.0b5
1.4.1b1
1.4.1b2
1.4.1b3
1.5.0
1.5.1b1
1.5.1b2
1.6.0b1
2.0.1b2
2.0.1b3
2.0.2
2.0.3a1
2.0.3a2
2.0.3a3
2.0.3a4
2.0.3a5
2.0.3a6
2.0.3a7
2.1.0
2.10.3b1
2.10.4
2.10.4b1
2.10.4b2
2.10.5
2.2.0
2.2.0.dev1
2.2.0a1
2.2.0a2
2.2.0a3
2.2.0a4
2.2.0a5
2.2.0a6
2.2.1
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.11a1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.0a7
2.5.0a8
2.5.0a9
2.5.1
2.5.2
2.5.3
2.5.4
2.5.4b1
2.5.5
2.5.6
2.5.7
2.5.8
2.6.0
2.6.0a1
2.6.0a2
2.6.0a3
2.6.0a4
2.6.1
2.7.0
2.7.0a1
2.7.0a2
2.7.0a3
2.7.1
2.8.0a1
2.8.0a2
2.8.0a3
2.8.0a4
2.8.0a5
2.8.0a6
2.8.0a7
2.8.0a8
2.8.0a9
2.8.1
2.8.2
2.8.2a1
2.8.3
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
2.9.0a3
2.9.0a5
2.9.0b1
2.9.0b2
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5
2.9.7
Fixed in
2.10.6
References Updated Jul 13, 2026 · Source: OSV.dev |
2.9.2
patch
Dependencies (22)
+ 14 more |
|
2.9.1
minor
1 CVE
CVE-2025-67796
PYSEC-2026-3048
GHSA-v4gp-hf5j-4566
Jul 13, 2026
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
IKUS Rdiffweb version 2.10.5 and below have an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6. Affected versions
0.10.0
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.9.2.dev1
0.9.3
0.9.4
+ 132 more Show less
0.9.5
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.1b1
1.3.1b2
1.3.2
1.4.0
1.4.0b1
1.4.0b2
1.4.0b3
1.4.0b4
1.4.0b5
1.4.1b1
1.4.1b2
1.4.1b3
1.5.0
1.5.1b1
1.5.1b2
1.6.0b1
2.0.1b2
2.0.1b3
2.0.2
2.0.3a1
2.0.3a2
2.0.3a3
2.0.3a4
2.0.3a5
2.0.3a6
2.0.3a7
2.1.0
2.10.3b1
2.10.4
2.10.4b1
2.10.4b2
2.10.5
2.2.0
2.2.0.dev1
2.2.0a1
2.2.0a2
2.2.0a3
2.2.0a4
2.2.0a5
2.2.0a6
2.2.1
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.11a1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.0a7
2.5.0a8
2.5.0a9
2.5.1
2.5.2
2.5.3
2.5.4
2.5.4b1
2.5.5
2.5.6
2.5.7
2.5.8
2.6.0
2.6.0a1
2.6.0a2
2.6.0a3
2.6.0a4
2.6.1
2.7.0
2.7.0a1
2.7.0a2
2.7.0a3
2.7.1
2.8.0a1
2.8.0a2
2.8.0a3
2.8.0a4
2.8.0a5
2.8.0a6
2.8.0a7
2.8.0a8
2.8.0a9
2.8.1
2.8.2
2.8.2a1
2.8.3
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
2.9.0a3
2.9.0a5
2.9.0b1
2.9.0b2
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5
2.9.7
Fixed in
2.10.6
References Updated Jul 13, 2026 · Source: OSV.dev |
2.9.1
minor
Dependencies (22)
+ 14 more |
|
2.9.0b2
pre
1 CVE
CVE-2025-67796
PYSEC-2026-3048
GHSA-v4gp-hf5j-4566
Jul 13, 2026
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
IKUS Rdiffweb version 2.10.5 and below have an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6. Affected versions
0.10.0
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.9.2.dev1
0.9.3
0.9.4
+ 132 more Show less
0.9.5
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.1b1
1.3.1b2
1.3.2
1.4.0
1.4.0b1
1.4.0b2
1.4.0b3
1.4.0b4
1.4.0b5
1.4.1b1
1.4.1b2
1.4.1b3
1.5.0
1.5.1b1
1.5.1b2
1.6.0b1
2.0.1b2
2.0.1b3
2.0.2
2.0.3a1
2.0.3a2
2.0.3a3
2.0.3a4
2.0.3a5
2.0.3a6
2.0.3a7
2.1.0
2.10.3b1
2.10.4
2.10.4b1
2.10.4b2
2.10.5
2.2.0
2.2.0.dev1
2.2.0a1
2.2.0a2
2.2.0a3
2.2.0a4
2.2.0a5
2.2.0a6
2.2.1
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.11a1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.0a7
2.5.0a8
2.5.0a9
2.5.1
2.5.2
2.5.3
2.5.4
2.5.4b1
2.5.5
2.5.6
2.5.7
2.5.8
2.6.0
2.6.0a1
2.6.0a2
2.6.0a3
2.6.0a4
2.6.1
2.7.0
2.7.0a1
2.7.0a2
2.7.0a3
2.7.1
2.8.0a1
2.8.0a2
2.8.0a3
2.8.0a4
2.8.0a5
2.8.0a6
2.8.0a7
2.8.0a8
2.8.0a9
2.8.1
2.8.2
2.8.2a1
2.8.3
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
2.9.0a3
2.9.0a5
2.9.0b1
2.9.0b2
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5
2.9.7
Fixed in
2.10.6
References Updated Jul 13, 2026 · Source: OSV.dev |
2.9.0b2
pre
Dependencies (22)
+ 14 more |
|
2.9.0b1
pre
1 CVE
CVE-2025-67796
PYSEC-2026-3048
GHSA-v4gp-hf5j-4566
Jul 13, 2026
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
IKUS Rdiffweb version 2.10.5 and below have an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6. Affected versions
0.10.0
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.9.2.dev1
0.9.3
0.9.4
+ 132 more Show less
0.9.5
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.1b1
1.3.1b2
1.3.2
1.4.0
1.4.0b1
1.4.0b2
1.4.0b3
1.4.0b4
1.4.0b5
1.4.1b1
1.4.1b2
1.4.1b3
1.5.0
1.5.1b1
1.5.1b2
1.6.0b1
2.0.1b2
2.0.1b3
2.0.2
2.0.3a1
2.0.3a2
2.0.3a3
2.0.3a4
2.0.3a5
2.0.3a6
2.0.3a7
2.1.0
2.10.3b1
2.10.4
2.10.4b1
2.10.4b2
2.10.5
2.2.0
2.2.0.dev1
2.2.0a1
2.2.0a2
2.2.0a3
2.2.0a4
2.2.0a5
2.2.0a6
2.2.1
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.11a1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.0a7
2.5.0a8
2.5.0a9
2.5.1
2.5.2
2.5.3
2.5.4
2.5.4b1
2.5.5
2.5.6
2.5.7
2.5.8
2.6.0
2.6.0a1
2.6.0a2
2.6.0a3
2.6.0a4
2.6.1
2.7.0
2.7.0a1
2.7.0a2
2.7.0a3
2.7.1
2.8.0a1
2.8.0a2
2.8.0a3
2.8.0a4
2.8.0a5
2.8.0a6
2.8.0a7
2.8.0a8
2.8.0a9
2.8.1
2.8.2
2.8.2a1
2.8.3
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
2.9.0a3
2.9.0a5
2.9.0b1
2.9.0b2
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5
2.9.7
Fixed in
2.10.6
References Updated Jul 13, 2026 · Source: OSV.dev |
2.9.0b1
pre
Dependencies (22)
+ 14 more |
|
2.9.0a5
pre
1 CVE
CVE-2025-67796
PYSEC-2026-3048
GHSA-v4gp-hf5j-4566
Jul 13, 2026
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
IKUS Rdiffweb version 2.10.5 and below have an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6. Affected versions
0.10.0
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.9.2.dev1
0.9.3
0.9.4
+ 132 more Show less
0.9.5
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.1b1
1.3.1b2
1.3.2
1.4.0
1.4.0b1
1.4.0b2
1.4.0b3
1.4.0b4
1.4.0b5
1.4.1b1
1.4.1b2
1.4.1b3
1.5.0
1.5.1b1
1.5.1b2
1.6.0b1
2.0.1b2
2.0.1b3
2.0.2
2.0.3a1
2.0.3a2
2.0.3a3
2.0.3a4
2.0.3a5
2.0.3a6
2.0.3a7
2.1.0
2.10.3b1
2.10.4
2.10.4b1
2.10.4b2
2.10.5
2.2.0
2.2.0.dev1
2.2.0a1
2.2.0a2
2.2.0a3
2.2.0a4
2.2.0a5
2.2.0a6
2.2.1
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.11a1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.0a7
2.5.0a8
2.5.0a9
2.5.1
2.5.2
2.5.3
2.5.4
2.5.4b1
2.5.5
2.5.6
2.5.7
2.5.8
2.6.0
2.6.0a1
2.6.0a2
2.6.0a3
2.6.0a4
2.6.1
2.7.0
2.7.0a1
2.7.0a2
2.7.0a3
2.7.1
2.8.0a1
2.8.0a2
2.8.0a3
2.8.0a4
2.8.0a5
2.8.0a6
2.8.0a7
2.8.0a8
2.8.0a9
2.8.1
2.8.2
2.8.2a1
2.8.3
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
2.9.0a3
2.9.0a5
2.9.0b1
2.9.0b2
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5
2.9.7
Fixed in
2.10.6
References Updated Jul 13, 2026 · Source: OSV.dev |
2.9.0a5
pre
Dependencies (22)
+ 14 more |
|
2.8.9
patch
1 CVE
CVE-2025-67796
PYSEC-2026-3048
GHSA-v4gp-hf5j-4566
Jul 13, 2026
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
IKUS Rdiffweb version 2.10.5 and below have an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6. Affected versions
0.10.0
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.9.2.dev1
0.9.3
0.9.4
+ 132 more Show less
0.9.5
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.1b1
1.3.1b2
1.3.2
1.4.0
1.4.0b1
1.4.0b2
1.4.0b3
1.4.0b4
1.4.0b5
1.4.1b1
1.4.1b2
1.4.1b3
1.5.0
1.5.1b1
1.5.1b2
1.6.0b1
2.0.1b2
2.0.1b3
2.0.2
2.0.3a1
2.0.3a2
2.0.3a3
2.0.3a4
2.0.3a5
2.0.3a6
2.0.3a7
2.1.0
2.10.3b1
2.10.4
2.10.4b1
2.10.4b2
2.10.5
2.2.0
2.2.0.dev1
2.2.0a1
2.2.0a2
2.2.0a3
2.2.0a4
2.2.0a5
2.2.0a6
2.2.1
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.11a1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.0a7
2.5.0a8
2.5.0a9
2.5.1
2.5.2
2.5.3
2.5.4
2.5.4b1
2.5.5
2.5.6
2.5.7
2.5.8
2.6.0
2.6.0a1
2.6.0a2
2.6.0a3
2.6.0a4
2.6.1
2.7.0
2.7.0a1
2.7.0a2
2.7.0a3
2.7.1
2.8.0a1
2.8.0a2
2.8.0a3
2.8.0a4
2.8.0a5
2.8.0a6
2.8.0a7
2.8.0a8
2.8.0a9
2.8.1
2.8.2
2.8.2a1
2.8.3
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
2.9.0a3
2.9.0a5
2.9.0b1
2.9.0b2
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5
2.9.7
Fixed in
2.10.6
References Updated Jul 13, 2026 · Source: OSV.dev |
2.8.9
patch
Dependencies (22)
+ 14 more |
|
2.9.0a3
pre
1 CVE
CVE-2025-67796
PYSEC-2026-3048
GHSA-v4gp-hf5j-4566
Jul 13, 2026
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
IKUS Rdiffweb version 2.10.5 and below have an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6. Affected versions
0.10.0
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.9.2.dev1
0.9.3
0.9.4
+ 132 more Show less
0.9.5
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.1b1
1.3.1b2
1.3.2
1.4.0
1.4.0b1
1.4.0b2
1.4.0b3
1.4.0b4
1.4.0b5
1.4.1b1
1.4.1b2
1.4.1b3
1.5.0
1.5.1b1
1.5.1b2
1.6.0b1
2.0.1b2
2.0.1b3
2.0.2
2.0.3a1
2.0.3a2
2.0.3a3
2.0.3a4
2.0.3a5
2.0.3a6
2.0.3a7
2.1.0
2.10.3b1
2.10.4
2.10.4b1
2.10.4b2
2.10.5
2.2.0
2.2.0.dev1
2.2.0a1
2.2.0a2
2.2.0a3
2.2.0a4
2.2.0a5
2.2.0a6
2.2.1
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.11a1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.0a7
2.5.0a8
2.5.0a9
2.5.1
2.5.2
2.5.3
2.5.4
2.5.4b1
2.5.5
2.5.6
2.5.7
2.5.8
2.6.0
2.6.0a1
2.6.0a2
2.6.0a3
2.6.0a4
2.6.1
2.7.0
2.7.0a1
2.7.0a2
2.7.0a3
2.7.1
2.8.0a1
2.8.0a2
2.8.0a3
2.8.0a4
2.8.0a5
2.8.0a6
2.8.0a7
2.8.0a8
2.8.0a9
2.8.1
2.8.2
2.8.2a1
2.8.3
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
2.9.0a3
2.9.0a5
2.9.0b1
2.9.0b2
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5
2.9.7
Fixed in
2.10.6
References Updated Jul 13, 2026 · Source: OSV.dev |
2.9.0a3
pre
Dependencies (22)
+ 14 more |
|
2.8.8
patch
1 CVE
CVE-2025-67796
PYSEC-2026-3048
GHSA-v4gp-hf5j-4566
Jul 13, 2026
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
IKUS Rdiffweb version 2.10.5 and below have an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6. Affected versions
0.10.0
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.9.2.dev1
0.9.3
0.9.4
+ 132 more Show less
0.9.5
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.1b1
1.3.1b2
1.3.2
1.4.0
1.4.0b1
1.4.0b2
1.4.0b3
1.4.0b4
1.4.0b5
1.4.1b1
1.4.1b2
1.4.1b3
1.5.0
1.5.1b1
1.5.1b2
1.6.0b1
2.0.1b2
2.0.1b3
2.0.2
2.0.3a1
2.0.3a2
2.0.3a3
2.0.3a4
2.0.3a5
2.0.3a6
2.0.3a7
2.1.0
2.10.3b1
2.10.4
2.10.4b1
2.10.4b2
2.10.5
2.2.0
2.2.0.dev1
2.2.0a1
2.2.0a2
2.2.0a3
2.2.0a4
2.2.0a5
2.2.0a6
2.2.1
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.11a1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.0a7
2.5.0a8
2.5.0a9
2.5.1
2.5.2
2.5.3
2.5.4
2.5.4b1
2.5.5
2.5.6
2.5.7
2.5.8
2.6.0
2.6.0a1
2.6.0a2
2.6.0a3
2.6.0a4
2.6.1
2.7.0
2.7.0a1
2.7.0a2
2.7.0a3
2.7.1
2.8.0a1
2.8.0a2
2.8.0a3
2.8.0a4
2.8.0a5
2.8.0a6
2.8.0a7
2.8.0a8
2.8.0a9
2.8.1
2.8.2
2.8.2a1
2.8.3
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
2.9.0a3
2.9.0a5
2.9.0b1
2.9.0b2
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5
2.9.7
Fixed in
2.10.6
References Updated Jul 13, 2026 · Source: OSV.dev |
2.8.8
patch
Dependencies (22)
+ 14 more |
|
2.8.7
patch
1 CVE
CVE-2025-67796
PYSEC-2026-3048
GHSA-v4gp-hf5j-4566
Jul 13, 2026
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
IKUS Rdiffweb version 2.10.5 and below have an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6. Affected versions
0.10.0
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.9.2.dev1
0.9.3
0.9.4
+ 132 more Show less
0.9.5
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.1b1
1.3.1b2
1.3.2
1.4.0
1.4.0b1
1.4.0b2
1.4.0b3
1.4.0b4
1.4.0b5
1.4.1b1
1.4.1b2
1.4.1b3
1.5.0
1.5.1b1
1.5.1b2
1.6.0b1
2.0.1b2
2.0.1b3
2.0.2
2.0.3a1
2.0.3a2
2.0.3a3
2.0.3a4
2.0.3a5
2.0.3a6
2.0.3a7
2.1.0
2.10.3b1
2.10.4
2.10.4b1
2.10.4b2
2.10.5
2.2.0
2.2.0.dev1
2.2.0a1
2.2.0a2
2.2.0a3
2.2.0a4
2.2.0a5
2.2.0a6
2.2.1
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.11a1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.0a7
2.5.0a8
2.5.0a9
2.5.1
2.5.2
2.5.3
2.5.4
2.5.4b1
2.5.5
2.5.6
2.5.7
2.5.8
2.6.0
2.6.0a1
2.6.0a2
2.6.0a3
2.6.0a4
2.6.1
2.7.0
2.7.0a1
2.7.0a2
2.7.0a3
2.7.1
2.8.0a1
2.8.0a2
2.8.0a3
2.8.0a4
2.8.0a5
2.8.0a6
2.8.0a7
2.8.0a8
2.8.0a9
2.8.1
2.8.2
2.8.2a1
2.8.3
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
2.9.0a3
2.9.0a5
2.9.0b1
2.9.0b2
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5
2.9.7
Fixed in
2.10.6
References Updated Jul 13, 2026 · Source: OSV.dev |
2.8.7
patch
Dependencies (22)
+ 14 more |
|
2.8.6
patch
1 CVE
CVE-2025-67796
PYSEC-2026-3048
GHSA-v4gp-hf5j-4566
Jul 13, 2026
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
IKUS Rdiffweb version 2.10.5 and below have an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6. Affected versions
0.10.0
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.9.2.dev1
0.9.3
0.9.4
+ 132 more Show less
0.9.5
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.1b1
1.3.1b2
1.3.2
1.4.0
1.4.0b1
1.4.0b2
1.4.0b3
1.4.0b4
1.4.0b5
1.4.1b1
1.4.1b2
1.4.1b3
1.5.0
1.5.1b1
1.5.1b2
1.6.0b1
2.0.1b2
2.0.1b3
2.0.2
2.0.3a1
2.0.3a2
2.0.3a3
2.0.3a4
2.0.3a5
2.0.3a6
2.0.3a7
2.1.0
2.10.3b1
2.10.4
2.10.4b1
2.10.4b2
2.10.5
2.2.0
2.2.0.dev1
2.2.0a1
2.2.0a2
2.2.0a3
2.2.0a4
2.2.0a5
2.2.0a6
2.2.1
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.11a1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.0a7
2.5.0a8
2.5.0a9
2.5.1
2.5.2
2.5.3
2.5.4
2.5.4b1
2.5.5
2.5.6
2.5.7
2.5.8
2.6.0
2.6.0a1
2.6.0a2
2.6.0a3
2.6.0a4
2.6.1
2.7.0
2.7.0a1
2.7.0a2
2.7.0a3
2.7.1
2.8.0a1
2.8.0a2
2.8.0a3
2.8.0a4
2.8.0a5
2.8.0a6
2.8.0a7
2.8.0a8
2.8.0a9
2.8.1
2.8.2
2.8.2a1
2.8.3
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
2.9.0a3
2.9.0a5
2.9.0b1
2.9.0b2
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5
2.9.7
Fixed in
2.10.6
References Updated Jul 13, 2026 · Source: OSV.dev |
2.8.6
patch
Dependencies (22)
+ 14 more |
|
2.8.5
patch
1 CVE
CVE-2025-67796
PYSEC-2026-3048
GHSA-v4gp-hf5j-4566
Jul 13, 2026
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
IKUS Rdiffweb version 2.10.5 and below have an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6. Affected versions
0.10.0
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.9.2.dev1
0.9.3
0.9.4
+ 132 more Show less
0.9.5
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.1b1
1.3.1b2
1.3.2
1.4.0
1.4.0b1
1.4.0b2
1.4.0b3
1.4.0b4
1.4.0b5
1.4.1b1
1.4.1b2
1.4.1b3
1.5.0
1.5.1b1
1.5.1b2
1.6.0b1
2.0.1b2
2.0.1b3
2.0.2
2.0.3a1
2.0.3a2
2.0.3a3
2.0.3a4
2.0.3a5
2.0.3a6
2.0.3a7
2.1.0
2.10.3b1
2.10.4
2.10.4b1
2.10.4b2
2.10.5
2.2.0
2.2.0.dev1
2.2.0a1
2.2.0a2
2.2.0a3
2.2.0a4
2.2.0a5
2.2.0a6
2.2.1
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.11a1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.0a7
2.5.0a8
2.5.0a9
2.5.1
2.5.2
2.5.3
2.5.4
2.5.4b1
2.5.5
2.5.6
2.5.7
2.5.8
2.6.0
2.6.0a1
2.6.0a2
2.6.0a3
2.6.0a4
2.6.1
2.7.0
2.7.0a1
2.7.0a2
2.7.0a3
2.7.1
2.8.0a1
2.8.0a2
2.8.0a3
2.8.0a4
2.8.0a5
2.8.0a6
2.8.0a7
2.8.0a8
2.8.0a9
2.8.1
2.8.2
2.8.2a1
2.8.3
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
2.9.0a3
2.9.0a5
2.9.0b1
2.9.0b2
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5
2.9.7
Fixed in
2.10.6
References Updated Jul 13, 2026 · Source: OSV.dev |
2.8.5
patch
Dependencies (22)
+ 14 more |
|
2.8.4
patch
1 CVE
CVE-2025-67796
PYSEC-2026-3048
GHSA-v4gp-hf5j-4566
Jul 13, 2026
IKUS Rdiffweb allows an attacker with any valid or stolen access token to act as other users
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
IKUS Rdiffweb version 2.10.5 and below have an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users data and, in some cases, perform privileged actions. This issue may enable cross-tenant access. Fixed in version 2.10.6. Affected versions
0.10.0
0.10.2
0.10.3
0.10.4
0.10.5
0.10.6
0.10.7
0.10.8
0.10.9
0.9.2.dev1
0.9.3
0.9.4
+ 132 more Show less
0.9.5
1.0.0
1.0.0a1
1.0.0a2
1.0.0a3
1.0.0a4
1.0.1
1.0.2
1.0.3
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.1b1
1.3.1b2
1.3.2
1.4.0
1.4.0b1
1.4.0b2
1.4.0b3
1.4.0b4
1.4.0b5
1.4.1b1
1.4.1b2
1.4.1b3
1.5.0
1.5.1b1
1.5.1b2
1.6.0b1
2.0.1b2
2.0.1b3
2.0.2
2.0.3a1
2.0.3a2
2.0.3a3
2.0.3a4
2.0.3a5
2.0.3a6
2.0.3a7
2.1.0
2.10.3b1
2.10.4
2.10.4b1
2.10.4b2
2.10.5
2.2.0
2.2.0.dev1
2.2.0a1
2.2.0a2
2.2.0a3
2.2.0a4
2.2.0a5
2.2.0a6
2.2.1
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.11a1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.0a7
2.5.0a8
2.5.0a9
2.5.1
2.5.2
2.5.3
2.5.4
2.5.4b1
2.5.5
2.5.6
2.5.7
2.5.8
2.6.0
2.6.0a1
2.6.0a2
2.6.0a3
2.6.0a4
2.6.1
2.7.0
2.7.0a1
2.7.0a2
2.7.0a3
2.7.1
2.8.0a1
2.8.0a2
2.8.0a3
2.8.0a4
2.8.0a5
2.8.0a6
2.8.0a7
2.8.0a8
2.8.0a9
2.8.1
2.8.2
2.8.2a1
2.8.3
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
2.9.0a3
2.9.0a5
2.9.0b1
2.9.0b2
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5
2.9.7
Fixed in
2.10.6
References Updated Jul 13, 2026 · Source: OSV.dev |
2.8.4
patch
Dependencies (22)
+ 14 more |