🔐 CVE Alert

CVE-2026-5774

UNKNOWN 0.0

Juju API Server Denial of Service and Authentication Replay via Unsynchronized Token Map

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause a denial of service on the server or possibly reuse a single-use discharge token.

CWE CWE-362
Vendor canonical
Product juju
Ecosystems
Industries
Technology
Published Apr 10, 2026
Last Updated Apr 10, 2026
Stay Ahead of the Next One

Get instant alerts for canonical juju

Be the first to know when new unknown vulnerabilities affecting canonical juju are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Canonical / Juju
2.0.0 < 2.9.57 3.0.0 < 3.6.21 4.0.0 < 4.0.6

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/juju/juju/security/advisories/GHSA-7m55-2hr4-pw78 github.com: https://github.com/juju/juju/pull/22206 github.com: https://github.com/juju/juju/pull/22205