[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 4605-1] python-flask-httpauth security update



-------------------------------------------------------------------------
Debian LTS Advisory DLA-4605-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                       Emmanuel Arias
May 28, 2026                                  https://wiki.debian.org/LTS
-------------------------------------------------------------------------

Package        : python-flask-httpauth
Version        : 3.2.4-3.1+deb11u1
CVE ID         : CVE-2026-34531
Debian Bug     : 1132581

A vulnerability was found in python-flask-httpauth, a Flask extension that
simplifies the use of HTTP authentication with Flask routes, that in a situation
where the client makes a request to a token protected resource without passing a
token, or passing an empty token, python-flask-httpauth would invoke the
application's token verification callback function with the token argument set
to an empty string. If the application had any users in its database with an
empty string set as their token, then it could potentially authenticate the
client request against any of those users.

For Debian 11 bullseye, this problem has been fixed in version
3.2.4-3.1+deb11u1.

We recommend that you upgrade your python-flask-httpauth packages.

For the detailed security status of python-flask-httpauth please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/python-flask-httpauth

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Attachment: signature.asc
Description: PGP signature


Reply to: