๐Ÿ” CVE Alert

CVE-2026-82468

MEDIUM 4.7

Rodauth before 2.47.0 CSRF Protection Bypass via Content-Type

CVSS Score
4.7
EPSS Score
0.0%
EPSS Percentile
0th

Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types containing application/json substrings to bypass CSRF token validation and force victims to authenticate to attacker-controlled accounts.

CWE CWE-352
Vendor jeremyevans
Product rodauth
Published Aug 29, 2026
Stay Ahead of the Next One

Get instant alerts for jeremyevans rodauth

Be the first to know when new medium vulnerabilities affecting jeremyevans rodauth are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

jeremyevans / rodauth
0 < 2.47.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/jeremyevans/rodauth/commit/3e0d7ab2d49a5733d1afcaaf1062b8a8258aa57a github.com: https://github.com/jeremyevans/rodauth/security/advisories/GHSA-hh2f-xw94-5p79 github.com: https://github.com/jeremyevans/rodauth vulncheck.com: https://www.vulncheck.com/advisories/rodauth-before-2.47.0-csrf-protection-bypass-via-content-type

Credits

Joshua Rogers (AISLE Research)