scitokens
SciToken reference implementation library
Activity
- Latest release
- 6mo ago
- Total releases
- 34
- Cadence
- ~4 days
- Last 12 months
- 2
Details
- License
- Apache-2.0
- First release
- Sep 13, 2017
| Version | Released | |
|---|---|---|
1.9.7
patch
|
1.9.7
patch
Dependencies (6)
|
|
1.9.6
minor
1 CVE
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.9.6
minor
Dependencies (6)
|
|
1.8.1
patch
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.8.1
patch
Dependencies (4)
|
|
1.8.0
minor
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.8.0
minor
Dependencies (4)
|
|
1.7.4
patch
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.7.4
patch
Dependencies (4)
|
|
1.7.2
patch
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.7.2
patch
Dependencies (4)
|
|
1.7.1
patch
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.7.1
patch
Dependencies (4)
|
|
1.7.0
minor
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.7.0
minor
Dependencies (3)
|
|
1.6.2
patch
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.6.2
patch
Dependencies (3)
|
|
1.6.0
minor
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.6.0
minor
Dependencies (3)
|
|
1.5.0
minor
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.5.0
minor
Dependencies (3)
|
|
1.4.0
minor
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.4.0
minor
Dependencies (3)
|
|
1.3.1
minor
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.3.1
minor
Dependencies (3)
|
|
1.2.4
patch
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.2.4
patch
|
|
1.2.2
patch
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.2.2
patch
|
|
1.2.1
patch
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.2.1
patch
|
|
1.2.0
minor
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.2.0
minor
|
|
1.1.1
patch
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.1.1
patch
|
|
1.1.0
minor
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.1.0
minor
|
|
1.0.2
patch
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.0.2
patch
|
|
1.0.1
patch
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.0.1
patch
|
|
1.0.0
major
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
1.0.0
major
|
|
0.3.3
patch
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
0.3.3
patch
|
|
0.3.2
patch
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
0.3.2
patch
|
|
0.3.1
patch
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
0.3.1
patch
|
|
0.3.0
minor
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
0.3.0
minor
|
|
0.2.2
patch
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
0.2.2
patch
|
|
0.2.1
minor
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
0.2.1
minor
|
|
0.1.6
patch
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
0.1.6
patch
|
|
0.1.5
patch
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
0.1.5
patch
|
|
0.1.4
patch
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
0.1.4
patch
|
|
0.1.3
patch
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
0.1.3
patch
|
|
0.1.1
patch
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
0.1.1
patch
|
|
0.1
initial
3 CVEs
CVE-2026-32714
PYSEC-2026-530
GHSA-rh5m-2482-966c
Jun 29, 2026
SciTokens is vulnerable to SQL Injection in KeyCache
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryThe Ran the POC below locally. DetailsFile: Vulnerable Code Snippets1. In
2. In
3. In
4. In
5. In
PoC
ImpactAn attacker who can influence the
MITIGATION AND WORKAROUNDSReplace string formatting with parameterized queries using the DB-API's placeholder syntax (e.g., Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-32727
GHSA-3x2w-63fp-3qvw
PYSEC-2026-2277
Mar 31, 2026
SciTokens has an Authorization Bypass via Path Traversal in Scope Validation
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: DescriptionWhen a token is verified, the If a token has a scope like Vulnerable Logic Flow:
Bypassing with URL Encoding:Since Root Traversal:A scope like ImpactAn attacker who can influence the Proof of ConceptThe following examples demonstrate the bypass (see
Recommended FixValidate that the path in the scope does not contain Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 21 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
1.9.6
Fixed in
1.9.7
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-32716
GHSA-w8fp-g9rh-34jh
PYSEC-2026-2276
Mar 31, 2026
SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryThe DetailsFile: Vulnerable Code Snippets:In
In
If PoC
ImpactThis bug allows a user to access resources they are not authorized for. For example, if a system uses usernames as top-level directories in a shared storage, a user Affected versions
0.1
0.1.1
0.1.3
0.1.4
0.1.5
0.1.6
0.2.1
0.2.2
0.3.0
0.3.1
0.3.2
0.3.3
+ 20 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.2.4
1.3.1
1.4.0
1.5.0
1.6.0
1.6.2
1.7.0
1.7.1
1.7.2
1.7.4
1.8.0
1.8.1
Fixed in
1.9.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
0.1
initial
|