Vulnerabilities (CVE)

Filtered by vendor Fastapi-users Project
Filtered by product Fastapi Users
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-68481 1 Fastapi-users Project 1 Fastapi Users 2026-03-05 N/A 5.9 MEDIUM
FastAPI Users allows users to quickly add a registration and authentication system to their FastAPI project. Prior to version 15.0.2, the OAuth login state tokens are completely stateless and carry no per-request entropy or any data that could link them to the session that initiated the OAuth flow. `generate_state_token()` is always called with an empty `state_data` dict, so the resulting JWT only contains the fixed audience claim plus an expiration timestamp. On callback, the library merely che ...

Show More